ZeroDayShield
An independent zero-day research engine for the open-source supply chain: npm packages, MCP servers, Docker images and Hugging Face models.
Overview
Malicious packages and poisoned models reach production through registries developers trust. ZeroDayShield watches four of those registries continuously and flags suspicious artifacts for disclosure.
I lead the project and built it from scratch, from the analysis engines to the live feed.
How it works
From a new upload on a registry to an entry on the public feed:
Watch the registries
New artifacts are pulled from the npm registry, Docker Hub and GHCR, the MCP registry and the Hugging Face Hub.
Analyze, from scratch
More than 50 static analysis engines, written without open-source analysis libraries, extract risk signals from each artifact. From live registry traffic they have mined 49,522 signals so far.
Cross-check known threats
Signals are cross-referenced against 228,020 known-malicious packages.
Triage with LLMs
A multi-stage LLM triage pipeline ranks what is left, so a human only reviews what matters. On the OSSF malicious-packages corpus it reached 100% recall and 93% precision, at 15× lower cost than the baseline.
Publish
Confirmed findings go to the live feed with severity, CWE class and the triage model’s confidence.
Why four ecosystems
Supply-chain attacks no longer stop at npm. MCP servers hand tools to AI agents, Docker images ship whole runtimes, and model files on Hugging Face can carry executable payloads such as pickle deserialization backdoors. One engine covers all four, so the same signals and triage apply everywhere.