NYU
Software Supply Chain Security Operations Center
Securing the Foundations
of Modern Software
We're building the capability to surface and address threats across the open-source ecosystems that modern software relies on.
A Research Center Dedicated To Software Supply-Chain Security
Modern software is built on open-source foundations. 98% of analyzed codebases contain open-source components, with the average application depending on over 1,180 such packages. This creates an enormous, constantly shifting attack surface no single organization can monitor alone.
NSOC applies the open-source intelligence of ecosyste.ms to continuously monitor the ecosystems that feed enrolled projects, tracking dependency changes, new attack vectors, and anomalous package behavior to alert organizations before exposure becomes an incident.
Hosted at NYU, NSOC brings together master's students, PhD researchers, and postdoctoral associates under the supervision of world-class faculty and practitioners.
Source
Maintainer CompromiseBuild
Poisoned CI RunnerPublish
Account TakeoverResolve
Dependency ConfusionInstall
Malicious PostinstallThe Four Pillars of Operation
NSOC integrates human ecosystem expertise, AI tooling, and continuous monitoring.
01 Connect
Students serve as dedicated liaisons to specific open-source ecosystems. Before engaging as security researchers, each student undergoes structured onboarding in the norms and culture of their ecosystem, building the credibility that makes security conversations possible.
02 Inspect
AI-driven vulnerability detection at unprecedented scale. Students develop and extend fuzzing frameworks, LLM-assisted code review pipelines, and automated patch generation agents. With a prize-winner of the DARPA AIxCC challenge, NSOC's AI-assisted research pushes the frontier forward.
03 Detect
Continuous monitoring powered by ecosyste.ms, covering dependency changes, anomalous package behavior, suspicious injections, and unmaintained critical components. NSOC coordinates responsible disclosure through ecosystem liaisons.
04 Direct
Annual ecosystem report cards assess security posture across trusted publishing adoption, dependency hygiene, and vulnerability responsiveness. NSOC delivers direct code integrations and coordinates with OpenSSF, NIST, and ecosystem governance bodies.
Team

Prof. Justin Cappos
NYU TandonThe “father of software supply chain security”. A creator of TUF, Uptane, gittuf, in-toto, and Git's tag security architecture, technologies deployed in millions of devices and across critical global infrastructure.

Prof. Jiahao Yu
NYU Abu DhabiCyber-AI expert focused on AI-driven vulnerability discovery, fuzzing, and automated patch generation. His team won a $3M prize in the DARPA AI Cyber Challenge (AIxCC).

Andrew Nesbitt
Founder, ecosyste.msFounder of ecosyste.ms. One of the foremost researchers performing security data analysis at open-source scale, with deep expertise in large-scale ecosystem intelligence and AI-powered cybersecurity tooling.

Vlad-Stefan Harbuz
Founder, Software Stewardship LabOpen source sustainability researcher. Director of the Open Source Pledge, which has raised $7,156,281 for maintainers. Helped build software used by the Gates Foundation to allocate $1B in healthcare funding.
Get in touch
Whether you're a student interested in joining, an organization looking to enroll, or a researcher interested in collaboration, we'd like to hear from you.
Email NSOCJoin NSOC
If you're an NYU student interested in joining the team, stay tuned for updates!