SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Python Malware Projects
-
hosts
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
Project mention: uBlock Origin is no longer available on the Chrome Store | news.ycombinator.com | 2025-03-10uBlock Origin still works in Firefox. https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
And you can, I believe, still just modify your hosts table to block out ads in Chrome. https://github.com/StevenBlack/hosts
Or your router's DNS using something like NextDNS. https://nextdns.io/
Ads suck. Support content where you can, but even when you pay they still serve ads / tracking scripts. So fuck 'em. Block all the ads.
-
CodeRabbit
CodeRabbit: AI Code Reviews for Developers. Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.
-
-
theZoo
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
The analyzed sample is provided within this folder, the password for the zip file is infected. This sample was taken from theZoo Repository.
-
We were given a quite big 20250312.mem file. Looking at the name of the challenge and the size of the file, it was clear it was required to use volatility.
-
-
pyWhat
🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙♀️
Project mention: pyWhat VS binwalk - a user suggested alternative | libhunt.com/r/pyWhat | 2024-07-19 -
Project mention: Qiling: A True Instrumentable Binary Emulation Framework | news.ycombinator.com | 2024-04-01
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
-
malwoverview
Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, InQuest, VxExchange and IPInfo, and it is also able to scan Android devices against VT.
-
Clone the Volatility 3 repository: > git clone https://github.com/volatilityfoundation/volatility3.git
-
-
-
-
-
-
intelmq
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
-
opensquat
The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains and brands.
-
packj
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
Project mention: A Study of Malware Prevention in Linux Distributions | news.ycombinator.com | 2024-11-21Good to see Packj[1] as one of the malware scanners used.
1. https://github.com/ossillate-inc/packj
Packj detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).
-
-
Project mention: MISP galaxy – cybersecurity and other related knowledge base | news.ycombinator.com | 2024-05-20
-
-
gmailc2
A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions
-
Safe-and-Stable-Ckpt2Safetensors-Conversion-Tool-GUI
Convert your Stable Diffusion checkpoints quickly and easily.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
Python Malware discussion
Python Malware related posts
-
💀 Insomni'hack 2025 CTF write-up
-
Malware Analysis: CryptoLocker
-
Tell HN: I just updated my wife's Chrome, and uBlock is no longer supported
-
A Study of Malware Prevention in Linux Distributions
-
pyWhat VS binwalk - a user suggested alternative
2 projects | 19 Jul 2024 -
Cyber Scarecrow, making your computer look 'scary' to malware
-
Qiling: A True Instrumentable Binary Emulation Framework
-
A note from our sponsor - SaaSHub
www.saashub.com | 18 Mar 2025
Index
What are some of the best open-source Malware projects in Python? This list will help you:
# | Project | Stars |
---|---|---|
1 | hosts | 27,678 |
2 | wifiphisher | 13,633 |
3 | theZoo | 11,667 |
4 | volatility | 7,571 |
5 | maltrail | 6,794 |
6 | pyWhat | 6,768 |
7 | qiling | 5,312 |
8 | flare-floss | 3,449 |
9 | malwoverview | 3,114 |
10 | volatility3 | 2,938 |
11 | APT_REPORT | 2,514 |
12 | CAPEv2 | 2,247 |
13 | yarGen | 1,615 |
14 | ThePhish | 1,196 |
15 | drakvuf-sandbox | 1,105 |
16 | intelmq | 999 |
17 | opensquat | 767 |
18 | packj | 661 |
19 | Python-Rootkit | 603 |
20 | misp-galaxy | 557 |
21 | MalConfScan | 483 |
22 | gmailc2 | 466 |
23 | Safe-and-Stable-Ckpt2Safetensors-Conversion-Tool-GUI | 446 |