Ossprey Raises $2.65M to Detect Malicious Open-Source Code

Image credit : Ossprey
Modern software is assembled as much as it is written.
Developers routinely pull libraries, frameworks and packages created outside their companies. That model makes software faster to build, but it also gives attackers a direct route into trusted development workflows.
London-based Ossprey has raised $2.65 million in oversubscribed pre-seed funding to identify malicious open-source packages before they reach developer machines or production environments.
The round was led by Episode 1 Ventures, with participation from Osney Capital and Octopus Investments.
Founded by Nate Dunning, the company’s CEO, and CTO David R., Ossprey was created by engineers with backgrounds across application security, engineering and security operations.
A package can be dangerous without being vulnerable
Traditional software security tools are largely built to find known weaknesses.
They compare code and dependencies against vulnerability databases, signatures and previously documented threats. That approach is useful when the industry already understands the problem.
A malicious package is different. It may contain no accidental flaw waiting to be exploited. The package itself may be designed to steal credentials, access systems or execute harmful code as soon as it is installed.
That distinction is central to Ossprey’s product. The company continuously analyzes packages across major open-source ecosystems and looks for malicious behavior before a threat has been formally catalogued.
The objective is to stop the package before it becomes part of an application, rather than alerting a security team after the code has already moved through the build process.
Faster coding is creating a larger attack surface
AI coding assistants are helping engineering teams generate and ship software more quickly. They are also increasing the volume of dependencies entering applications.
Developers may accept an AI-generated package recommendation without manually inspecting every line of its source code. Attackers can exploit that speed by publishing lookalike packages, compromising maintainers or placing malicious updates inside projects that appear legitimate.
Ossprey is designed to work inside that faster development environment without forcing every dependency through a slow manual review.
The company says its platform runs quietly in the background and is intended to protect software pipelines without adding unnecessary friction for developers.
One security problem, not another crowded platform
Ossprey is deliberately keeping its initial product scope narrow.
Rather than building a broad security suite covering compliance, cloud posture and vulnerability management, the startup is focused on one task: understanding what open-source code is attempting to do before an organization trusts it.
Its dashboards, integrations and reporting features are designed to support that specific detection problem rather than become separate product categories.
Since completing the funding round, Ossprey says it has expanded to a seven-person team, developed its platform and launched public scanning capabilities that are already identifying newly published malicious packages. These figures and performance claims are based on company information and have not been independently verified.
The difficult balance: stronger controls without slower releases
The financing will support product development, engineering recruitment, commercial hiring and international growth across the UK, Europe and North America. Ossprey also plans to pursue another funding round within the next year.
Its technical challenge is identifying genuinely malicious behavior without producing an overwhelming number of false alerts.
The commercial challenge is equally important. Security teams want tighter control over external code, while developers resist tools that interrupt releases or block legitimate dependencies.
Ossprey will therefore be judged on both detection quality and usability. Catching threats that existing scanners miss will matter, but so will whether engineering teams can keep the product enabled without treating it as another obstacle in the delivery pipeline.
Source : Ossprey Official Announcement
Trending News
More from Funding

Modo Energy Raises $30M to Standardize Electrification Asset Valuations
Building batteries, solar projects and data centers requires enormous amounts of capital. Deciding what those assets are worth still relies too heavily on disconnected models, static reports and inconsistent assumptions. Modo Energy has raised $30 million in Series B funding to build a more consistent valuation layer for the electrification economy. Molten Ventures led the […]






