Securing the Foundations
of Modern Software

We're building the capability to surface and address threats across the open-source ecosystems that modern software relies on.

14M+
packages monitored via ecosyste.ms
287M
repositories tracked
24.5B
dependencies indexed
65%
of organizations hit by supply chain attacks in 2025
About

A Research Center Dedicated To Software Supply-Chain Security

Modern software is built on open-source foundations. 98% of analyzed codebases contain open-source components, with the average application depending on over 1,180 such packages. This creates an enormous, constantly shifting attack surface no single organization can monitor alone.

NSOC applies the open-source intelligence of ecosyste.ms to continuously monitor the ecosystems that feed enrolled projects, tracking dependency changes, new attack vectors, and anomalous package behavior to alert organizations before exposure becomes an incident.

Hosted at NYU, NSOC brings together master's students, PhD researchers, and postdoctoral associates under the supervision of world-class faculty and practitioners.

NSOC Monitoring

Source

Maintainer Compromise

Build

Poisoned CI Runner

Publish

Account Takeover

Resolve

Dependency Confusion

Install

Malicious Postinstall
Research Areas

The Four Pillars of Operation

NSOC integrates human ecosystem expertise, AI tooling, and continuous monitoring.

01 Connect

Students serve as dedicated liaisons to specific open-source ecosystems. Before engaging as security researchers, each student undergoes structured onboarding in the norms and culture of their ecosystem, building the credibility that makes security conversations possible.

02 Inspect

AI-driven vulnerability detection at unprecedented scale. Students develop and extend fuzzing frameworks, LLM-assisted code review pipelines, and automated patch generation agents. With a prize-winner of the DARPA AIxCC challenge, NSOC's AI-assisted research pushes the frontier forward.

03 Detect

Continuous monitoring powered by ecosyste.ms, covering dependency changes, anomalous package behavior, suspicious injections, and unmaintained critical components. NSOC coordinates responsible disclosure through ecosystem liaisons.

04 Direct

Annual ecosystem report cards assess security posture across trusted publishing adoption, dependency hygiene, and vulnerability responsiveness. NSOC delivers direct code integrations and coordinates with OpenSSF, NIST, and ecosystem governance bodies.

Leadership

Team

A portrait of Prof. Justin Cappos

Prof. Justin Cappos

NYU Tandon

The “father of software supply chain security”. A creator of TUF, Uptane, gittuf, in-toto, and Git's tag security architecture, technologies deployed in millions of devices and across critical global infrastructure.

A portrait of Prof. Jiahao Yu

Prof. Jiahao Yu

NYU Abu Dhabi

Cyber-AI expert focused on AI-driven vulnerability discovery, fuzzing, and automated patch generation. His team won a $3M prize in the DARPA AI Cyber Challenge (AIxCC).

A portrait of Andrew Nesbitt

Andrew Nesbitt

Founder, ecosyste.ms

Founder of ecosyste.ms. One of the foremost researchers performing security data analysis at open-source scale, with deep expertise in large-scale ecosystem intelligence and AI-powered cybersecurity tooling.

A portrait of Vlad-Stefan Harbuz

Vlad-Stefan Harbuz

Founder, Software Stewardship Lab

Open source sustainability researcher. Director of the Open Source Pledge, which has raised $7,156,281 for maintainers. Helped build software used by the Gates Foundation to allocate $1B in healthcare funding.

Contact

Get in touch

Whether you're a student interested in joining, an organization looking to enroll, or a researcher interested in collaboration, we'd like to hear from you.

Email NSOC
Students

Join NSOC

If you're an NYU student interested in joining the team, stay tuned for updates!