Business Wire

Veracode Acquires Phylum, Inc. Technology to Transform Software Supply Chain Security

Share

Veracode, a global leader in application risk management, today announced it has acquired certain assets of Phylum, Inc., including its malicious package analysis, detection, and mitigation technology. The acquisition enhances Veracode’s ability to identify and block malicious code in open-source libraries, marking continued investment in its software supply chain risk management capabilities. This gives customers a more comprehensive view of risks associated with open-source code usage, strengthening their defenses against emerging threats.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250106967344/en/

Veracode acquires technology from Phylum, Inc. (Graphic: Business Wire)

With software supply chain attacks projected to triple in cost from $46 billion in 2023 to $138 billion by 20311, safeguarding against these risks is now mission-critical for organizations. Through Phylum’s innovative technology, Veracode empowers customers to proactively prevent attacks by identifying and blocking malicious packages and vulnerabilities in real time. The addition of a package management firewall and an unmatched malicious package database further strengthens Veracode’s ability to mitigate emerging software threats before they impact customers.

Ravi Iyer, Chief Product Officer at Veracode, said, “This acquisition advances Veracode’s mission to be the most comprehensive application risk management platform by significantly expanding our ability to identify, mitigate, and remediate risks across the software supply chain. With Phylum’s unmatched database and cutting-edge research—proven to detect 60 percent more malicious packages than any other vendor—our customers will gain the confidence to innovate faster, knowing their software is protected against evolving threats.”

Veracode Prevents, Detects and Fixes Malicious Packages

Malicious packages have become a prevalent attack vector in the software supply chain, capable of infecting networks, stealing sensitive information, and enabling remote code execution. Identifying and mitigating these threats is now a critical component of any robust software composition analysis (SCA) solution. Effective tools must go beyond detection to quarantine and block suspicious packages in real-time.

With Phylum’s fully automated malicious code analysis pipeline, Veracode significantly shortens the window of opportunity for attackers. Newly published packages are analyzed within seconds, helping customers proactively prevent attacks. Phylum’s recent research identified nearly half a million malicious packages, including 2,500 targeted malware campaigns aimed at industries like finance and cryptocurrency, demonstrating the scale and sophistication of these threats.

“Uniting Veracode’s platform and Phylum’s malicious package detection and mitigation technology creates exceptional value for our customers worldwide,” said Aaron Bray, CEO & Co-founder of Phylum, Inc. “By combining our advanced research capabilities with Veracode’s industry-leading platform, we’re expanding the fight against software supply chain threats. Together, we will deliver even greater protection and peace of mind to organizations navigating an increasingly complex threat landscape, and we are excited to join the team.”

Phylum’s technology, including its malicious package database and package management firewall, will be integrated into Veracode’s SCA product, with general availability expected early this year. The acquisition also bolsters Veracode’s renowned security research team with Phylum’s experts, further elevating the company’s ability to protect customers from evolving threats.

For more information about the acquisition and software supply chain security, contact the Veracode team.

1 Gartner Inc., “Leader’s Guide to Software Supply Chain Security”, June 20, 2024

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20250106967344/en/

Contacts

For more information, please contact:
Katy Gwilliam
kgwilliam@veracode.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

QPS Celebrates 30 th Anniversary4.6.2025 19:00:00 EEST | Press release

QPS Holdings, LLC (QPS), an award-winning contract research organization (CRO) focused on bioanalytics and clinical trials, is celebrating its 30-year anniversary in 2025. Founded by Dr. Benjamin Chien in 1995 to provide high-quality bioanalytical liquid chromatography with tandem mass spectrometry (LC-MS/MS) contract services, QPS is now recognized as a global leader in contract research. Over the past 30 years, the company has grown from a single office in Delaware, USA to a widely respected, global, full-service CRO with 8 locations spread across the US, EU, Asia, India and Australia, a clinical trial network of over 700 sites and an increased focus on leveraging the power of AI to accelerate clinical trials. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250604778675/en/ Dr. Benjamin Chien founder and CEO of QPS Holdings, LLC. Over the years, QPS has grown from a small molecule bioanalysis shop of three people to a globa

Cessna SkyCourier Combi Configuration Achieves Certification From the National Civil Aviation Agency of Brazil4.6.2025 18:30:00 EEST | Press release

The Cessna SkyCourier Combi configuration kit recently achieved certification from the National Civil Aviation Agency of Brazil (ANAC) and joined the fleet of Brazilian charter company Cleiton Táxi Aéreo (CTA). This marks the first delivery of the SkyCourier into South America. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250604928791/en/ The Cessna SkyCourier Combi configuration kit recently achieved certification from the National Civil Aviation Agency of Brazil (ANAC) and joined the fleet of Brazilian charter company Cleiton Táxi Aéreo (CTA). This marks the first delivery of the SkyCourier into South America. (Photo credit: Textron Aviation) The Cessna SkyCourier is designed and manufactured by Textron Aviation Inc., a Textron Inc. (NYSE: TXT) company. CTA recently took delivery of a passenger variant of the twin-engine, large-utility turboprop equipped with conversion kits that enable the standard 19-passenger interior

IFF Unveils Game-Changing Outlook on GLP-1 Consumers4.6.2025 18:00:00 EEST | Press release

IFF (NYSE: IFF), a global leader in food, beverage, and health and wellness, has released a new report highlighting how the rapidly growing GLP-1 consumer market is reshaping the sensory experience and nutritional needs associated with eating and drinking. The report outlines how food and beverage manufacturers can better support this emerging consumer segment with products that align with their evolving preferences. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250604818126/en/ “IFF is empowering our customers to lead the next wave of food and beverage innovations beyond traditional formulations, including helping GLP-1 consumers have choices they desire,” said Erik Fyrwald, IFF CEO. “We aim to bring back the joy of eating and drinking by offering more healthy, great-tasting nutrition choices for all consumer segments, including GLP-1 users.” Disconnect on three levels Despite the rapid rise in GLP-1 medication use, most f

Visa Cash App Racing Bulls (VCARB) Formula One™ Team Accelerates Racing Car Design with Neural Concept’s Engineering AI4.6.2025 17:04:00 EEST | Press release

Visa Cash App Racing Bulls Formula One™Team has deployed Neural Concept, the world’s leading AI platform for engineering design to accelerate the team’s car design and optimize aerodynamic performance through AI-powered, data-driven engineering workflows that enable faster design iteration and better-informed decisions. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250603592297/en/ Visa Cash App Red Bull - Racing Bulls and Neural Concept AI F1 vehicle partnership Neural Concept’s proprietary Engineering AI platform complements traditional Computational Fluid Dynamics (CFD) with high-speed predictive simulations. Engineers can use digital twins to evaluate thousands of design variants across complex “multi-physics” environments that mimic real-world track conditions such as wind and temperature differences. This enables VCARB to explore more designs, unlocking new performance gains within every iteration. Laurent Mekies, Tea

Money20/20 Europe Hosts Regulators' Closed-Door Roundtable to Accelerate Fintech Innovation4.6.2025 16:51:00 EEST | Press release

Money20/20, the world’s leading fintech show, and the place where money does business, hosted its Policy Exchange on June 3rd at Money20/20 Europe at the RAI in Amsterdam. Money20/20 Europe's Policy Exchange convened senior leaders from central banks, regulatory bodies, and industry to address three critical areas: post-MiCA crypto regulation, financial data access through Open Finance, and cross-border policy in collaboration with BIS. The exclusive closed-door event featured keynote addresses from Suzy Pallett, Executive Vice President of Money20/20 Europe and Gijs Boudewijn, incoming Chair Elect of the European Payments Council, followed by specialized roundtables that highlighted the need for harmonized regulations supporting innovation, security, and global cooperation. "Money20/20 Europe serves as an essential platform where regulators can gather for productive and future-focused discussions in a neutral environment," explained Suzy Pallett, Executive Vice President at, Money20/2

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye