Veracode Acquires Phylum, Inc. Technology to Transform Software Supply Chain Security
Technology Acquisition Delivers Automated Malicious Package Analysis, Detection, and Mitigation in Open-source Code
Veracode, a global leader in application risk management, today announced it has acquired certain assets of Phylum, Inc., including its malicious package analysis, detection, and mitigation technology. The acquisition enhances Veracode’s ability to identify and block malicious code in open-source libraries, marking continued investment in its software supply chain risk management capabilities. This gives customers a more comprehensive view of risks associated with open-source code usage, strengthening their defenses against emerging threats.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250106967344/en/

Veracode acquires technology from Phylum, Inc. (Graphic: Business Wire)
With software supply chain attacks projected to triple in cost from $46 billion in 2023 to $138 billion by 20311, safeguarding against these risks is now mission-critical for organizations. Through Phylum’s innovative technology, Veracode empowers customers to proactively prevent attacks by identifying and blocking malicious packages and vulnerabilities in real time. The addition of a package management firewall and an unmatched malicious package database further strengthens Veracode’s ability to mitigate emerging software threats before they impact customers.
Ravi Iyer, Chief Product Officer at Veracode, said, “This acquisition advances Veracode’s mission to be the most comprehensive application risk management platform by significantly expanding our ability to identify, mitigate, and remediate risks across the software supply chain. With Phylum’s unmatched database and cutting-edge research—proven to detect 60 percent more malicious packages than any other vendor—our customers will gain the confidence to innovate faster, knowing their software is protected against evolving threats.”
Veracode Prevents, Detects and Fixes Malicious Packages
Malicious packages have become a prevalent attack vector in the software supply chain, capable of infecting networks, stealing sensitive information, and enabling remote code execution. Identifying and mitigating these threats is now a critical component of any robust software composition analysis (SCA) solution. Effective tools must go beyond detection to quarantine and block suspicious packages in real-time.
With Phylum’s fully automated malicious code analysis pipeline, Veracode significantly shortens the window of opportunity for attackers. Newly published packages are analyzed within seconds, helping customers proactively prevent attacks. Phylum’s recent research identified nearly half a million malicious packages, including 2,500 targeted malware campaigns aimed at industries like finance and cryptocurrency, demonstrating the scale and sophistication of these threats.
“Uniting Veracode’s platform and Phylum’s malicious package detection and mitigation technology creates exceptional value for our customers worldwide,” said Aaron Bray, CEO & Co-founder of Phylum, Inc. “By combining our advanced research capabilities with Veracode’s industry-leading platform, we’re expanding the fight against software supply chain threats. Together, we will deliver even greater protection and peace of mind to organizations navigating an increasingly complex threat landscape, and we are excited to join the team.”
Phylum’s technology, including its malicious package database and package management firewall, will be integrated into Veracode’s SCA product, with general availability expected early this year. The acquisition also bolsters Veracode’s renowned security research team with Phylum’s experts, further elevating the company’s ability to protect customers from evolving threats.
For more information about the acquisition and software supply chain security, contact the Veracode team.
1 Gartner Inc., “Leader’s Guide to Software Supply Chain Security”, June 20, 2024
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20250106967344/en/

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Access Advance Announces HEVC Advance and VVC Advance Pricing through 203022.7.2025 02:00:00 CEST | Press release
Access Advance LLC (“Advance”) today announced the results of several significant decisions by the Licensors in both the HEVC Advance and VVC Advance Patent Pools. Both patent pools opted to maintain their current royalty rates and caps for Licensees who sign before December 31, 2025, and to extend an incentive that aligns the royalty caps for Advance’s Multi-Codec Bridging Agreement (“MCBA”) and the VVC Advance Patent Pool for Licensees who sign the MCBA during the same period. The result is that Licensees who join the HEVC Advance program, gaining access to more than 27,000 patents, on or before December 31, 2025, can lock in current rates and caps through 2030. This protection applies both to ongoing royalty obligations and calculation of royalties due for past sales. Additionally, both current and new HEVC Advance Licensees who join the VVC Advance Patent Pool and execute the MCBA by December 31, 2025, will enjoy MCBA royalty caps that match the royalty caps for the VVC Advance pro
Andersen Consulting tilføjer ekspertise inden for markedsadgang med Prime Action i Brasilien22.7.2025 00:50:00 CEST | Pressemeddelelse
Andersen Consulting styrker sin kapacitet i Latinamerika med tilføjelsen af samarbejdsfirmaet Prime Action Consulting, et firma med speciale i markedsadgangsstrategi og channel management inden for bil-, landbrugs-, bank-, medicinal- og telekommunikationssektoren. Prime Action leverer komplette kommercielle konsulenttjenester for at hjælpe organisationer med at optimere deres go-to-market-strategier og forbedre resultaterne på tværs af salgs- og distributionskanaler. Firmaets tilbud omfatter markedsadgangsstrategi, intelligent channel management, udarbejdelse af handels- og distributionspolitik, kanaludviklingstjenester og uddannelse, som alle er designet til at skabe effektivitet og kundetilpasning gennem strukturerede processer, standarder og målrettet eksekvering. Prime Action arbejder med førende virksomheder i hele Latinamerika og følger ikke blot kunderne fra planlægning til implementering, men også efter implementeringen, hvor de tilbyder relevant uddannelse og evaluering for at
MayMaan Launches Engine Integration Program to Accelerate Clean Combustion Deployment and Market Adoption21.7.2025 19:34:00 CEST | Press release
Company unveils a comprehensive framework to empower manufacturers, OEMs, distributors and service partners with drop-in clean combustion solutions MayMaan, a scale-up innovator, transforming combustion technology, is announcing a robust and scalable partnership model to support the transition to more efficient power systems across global industries whilst cutting harmful emissions such as NOx and SOx to levels that are practically immeasurable. At the heart of MayMaan’s offering is its proprietary AquaStroke® technology, which runs on a revolutionary 70% water and 30% ethanol fuel blend. This patented system delivers high torque and reliability while dramatically reducing emissions—offering a compelling alternative to diesel engines and electrification overhauls. “Our technology is more than a breakthrough—it’s a platform designed to help others succeed,” said Doron Shmueli, Founder and CEO at MayMaan. “From manufacturers to distributors, we provide a full solution—ready to integrate,
Armis Named a Leader in Unified Vulnerability Management Solutions, Q3 2025 Evaluation21.7.2025 17:25:00 CEST | Press release
Company achieved the highest score of all providers for its Current Offering Armis, the cyber exposure management & security company, today announced that it has been named a Leader in The Forrester Wave™: Unified Vulnerability Management Solutions, Q3 2025. In this Forrester Wave™, Armis is ranked a Leader and achieved the highest score in the Current Offering category. According to the report, “Armis’ strategy is grounded in proactive security principles… Armis is an excellent fit for either beginner organizations starting their proactive security journey or mature organizations that need leading vulnerability response capabilities.” “I believe Armis stood out as a Leader because Armis CentrixTM is different – it’s a platform built to help organizations reduce cyber risk, not just report on it,” said Yevgeny Dibrov, CEO and Co-Founder of Armis. “We are redefining what security should look like in a connected world, helping organizations move from passive defense to proactive control
DevvStream Completes $10M Initial Funding to Launch $300M Asset-Backed Digital Infrastructure and Sustainability Strategy21.7.2025 17:00:00 CEST | Press release
DevvStream Corp. (Nasdaq: DEVS) (“DevvStream” or the “Company”), a leading carbon management firm specializing in the development, investment, and sale of environmental assets, today announced that it has entered into a securities purchase agreement for the issuance of up to (US)$300 million in senior secured convertible notes (“Senior Notes”), advancing its strategic initiative to build a blockchain-based treasury and launch a tokenization platform for sustainability-linked infrastructure. The securities purchase agreement provides for the issuance of up to (US)$300 million in Senior Notes with Helena Partners, which issuances will be funded in multiple tranches. An initial funding of (US)$10 million was completed on July 18, 2025. Key Highlights: Under the agreement, DevvStream will allocate 75% of the net proceeds (70% of the initial tranche) toward the purchase of liquid digital assets that offer 24/7 liquidity, serve as non-correlated stores of value, and may be used as collateral
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom