Supply-chain threat feeds
Attributed indicators of compromise and vulnerability rules, regenerated continuously from the codelake corpus of confirmed-malicious and vulnerable packages across all major ecosystems. Every indicator carries the package and version it came from.
Five feeds, one endpoint.
Plain-text lists for quick blocklists, a STIX 2.1 bundle for your SIEM or TIP, and a WordPress ruleset — all served from feeds.codelake.dev.
Malicious domains text
C2 / exfil domains from confirmed-malicious packages.
Malicious IPs text
Raw-IP C2 / dead-drop endpoints (well-known public resolvers filtered out).
Malicious hashes text
SHA-256 of confirmed-malicious package artifacts.
STIX 2.1 bundle stix 2.1
The same indicators as a STIX 2.1 bundle for SIEM / TIP ingestion.
WordPress vuln rules json
BlockForge-format ruleset from confirmed WordPress vulnerabilities — public CVEs plus codelake’s own SAST.
Provided free as a defensive resource; each indicator is attributed to its emitting package and version. Questions or a richer / real-time API: research.codelake.dev
Every line is attributed.
Indicators are never anonymous. Each entry names the package and version it was extracted from, so you can verify a hit instead of trusting a list.
Pull it into your stack.
Blocklists & egress rules
Fetch the plain-text domain and IP lists on a cron and feed them into your firewall, DNS sinkhole or CI egress policy.
SIEM / TIP ingestion
The STIX 2.1 bundle carries the same indicators with full attribution, ready for MISP, OpenCTI or your SIEM’s threat-intel connector.
Artifact verification
Match SHA-256 hashes against packages already in your cache or lockfile to spot a confirmed-malicious artifact you have pulled.
No key, no quota, no catch.
The feeds are published as a defensive resource for the ecosystem — use them in commercial and non-commercial systems alike. Attribution to codelake Research is appreciated but not required.