discovered 03 Aug 2026
malcontent
→ View on GitHubMalcontent is a subtle malware discovery tool that leverages context, differential analysis, and over 14,500 YARA rules to uncover supply chain compromises, primarily targeting Linux binaries but also supporting other UNIX platforms and Windows. Its three operational modes—analyze, diff, and scan—facilitate extensive program capability assessments, risk-weighted comparisons, and threshold-based scanning. Key features include support for multiple binary formats, various output formats, integration within CI/CD pipelines, and specific configurations for handling archives and container images.