SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Python Malware Projects
-
hosts
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
For those who don't use it already, the following is a great compilation of curated block lists you can put into your etc/hosts file to block traffic :)
https://github.com/StevenBlack/hosts
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
-
theZoo
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
-
-
pyWhat
🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙♀️
-
I use Qiling [0] (built on top of Unicorn) sometimes for this kind of things (it can take application snapshots, that you can restore; and you can also use something similar to x86/x86-64 memory hardware breakpoints too). Might fit what you want, although it can sometimes be in a pain in the rear to set up...
[0] https://github.com/qilingframework/qiling
-
These techniques are force multipliers, not substitutes for forensic tools. They don't replace Autopsy, Volatility, or Plaso. The pattern is: Plaso builds the timeline, pandas lets you filter and analyze it; Volatility extracts memory artifacts, Python processes what Volatility extracts.
-
-
malwoverview
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
-
-
-
-
-
-
intelmq
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
-
opensquat
The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains and brands.
-
packj
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
Project mention: Packj flags malicious/risky open-source packages | news.ycombinator.com | 2026-05-22 -
-
-
-
gmailc2
A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions
-
Safe-and-Stable-Ckpt2Safetensors-Conversion-Tool-GUI
Convert your Stable Diffusion checkpoints quickly and easily.
-
Python Malware discussion
Python Malware related posts
-
I made my phone slow on purpose
-
Packj flags malicious/risky open-source packages
-
Do_not_track
-
Volatility: The volatile memory forensic extraction framework
-
The No Fakes Act Has a "Fingerprinting" Trap That Kills Open Source
-
Is Germany on the Brink of Banning Ad Blockers?
-
💀 Insomni'hack 2025 CTF write-up
-
A note from our sponsor - SaaSHub
www.saashub.com | 21 Jul 2026
Index
What are some of the best open-source Malware projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | hosts | 30,724 |
| 2 | wifiphisher | 14,559 |
| 3 | theZoo | 13,205 |
| 4 | maltrail | 8,553 |
| 5 | pyWhat | 7,212 |
| 6 | qiling | 6,016 |
| 7 | volatility3 | 4,255 |
| 8 | flare-floss | 4,093 |
| 9 | malwoverview | 3,948 |
| 10 | CAPEv2 | 3,366 |
| 11 | APT_REPORT | 3,056 |
| 12 | yarGen | 1,802 |
| 13 | ThePhish | 1,334 |
| 14 | drakvuf-sandbox | 1,317 |
| 15 | intelmq | 1,121 |
| 16 | opensquat | 977 |
| 17 | packj | 688 |
| 18 | misp-galaxy | 637 |
| 19 | Python-Rootkit | 637 |
| 20 | MalConfScan | 497 |
| 21 | gmailc2 | 487 |
| 22 | Safe-and-Stable-Ckpt2Safetensors-Conversion-Tool-GUI | 457 |
| 23 | debloat | 452 |