Malicious Package Detection Patents: Who Leads, Gaps 2026
- Concentrated at the top. A single leader holds 6 of 34 records, and the top 5 assignees together account for 61.8% of all 34 records in scope.
- A long tail below rank 10. The top 10 assignees cover 94.1% of the field, leaving only a handful of records spread across the remaining filers.
- Filing peaked in 2023. Six records published that year, the high point in a trend running from zero in 2017 to a still-partial 2026.
Top-5 share is the combined record count of the five largest assignees divided by all 34 records in scope (CR5), not by the ranked leaders only.
What this landscape covers
This landscape covers 34 published patent records matching malicious package detection, repository code integrity verification, install-script analysis, package signature checking, name-similarity detection, version pinning, repository access control, and behavior analysis, filed between 2015 and the 2026-07-31 cut-off. The search string pairs core detection concepts with the specific mechanisms — install scripts, signatures, typosquatting-style name similarity, version pinning, access control, and behavioral analysis — that distinguish a repository-security filing from generic malware detection art.
Because publication typically lags filing by around 18 months, the most recent one or two years in the trend understate actual filing activity; treat 2025 and 2026 figures as a floor, not a ceiling.
Let an AI agent run this analysis on your own technology
Pick a task. Every answer cites the patents behind it.
Filing trend and technology composition
Two views of the same 34-record dataset: how filing activity has moved year over year, and which IPC subclasses the records sit in.
Filing trend
Filings run from zero in 2017 to a peak of 6 in 2023, then continue into a partial 2026 count of 1. With fewer than four complete years remaining once the publication lag is accounted for, a growth rate cannot be reliably computed from this trend.
Technology composition by IPC subclass
G06F (electric digital data processing) covers 79.4% of the 34 records, confirming that most claims are framed as data-processing methods rather than network-layer or transaction-layer inventions. H04L (digital information transmission) appears in 38.2% of records, reflecting the network-transport side of package delivery and verification. G06Q (11.8%) and H04W (5.9%) are minority classes, tied to commerce-platform and wireless-specific filings respectively. Because a single record can carry multiple IPC classes, these shares sum to more than 100% of the record total.
Shares are the percentage of the 34 records in scope. A patent can carry several IPC classes, so the shares add up to more than 100%.
Go deeper on Malicious Package Detection in Repositories with Eureka
This page is one run against one query. Ask Eureka your own question about malicious package detection in repositories and every answer comes back with the patent numbers behind it.
Try EurekaRepresentative filing and most-cited records
Deploying a cloud-based system using a distributed ledger
Systems and methods for the deployment of cloud-based systems using a distributed ledger are disclosed. The system may include a cloud provider system and a distributed ledger. The cloud provider system may be configured to deploy cloud-based systems and APIs to enable one or more participant systems to leverage cloud-based resources. The distributed ledger may record events, functionalities, and operations from the cloud provider system, the participant systems, and the deployed cloud-based systems and APIs.Filed by American Express Travel Related Services, published 2020-12-17 as US20200394654A1.


| # | Publication no. | Patent title | Citations |
|---|---|---|---|
| 1 | US20180131574A1 | Remote server monitoring and patching system | 232 |
| 2 | US20160112262A1 | Installation and configuration of connected devices | 158 |
| 3 | US20170010874A1 | Provisioning storage devices in a data center | 55 |
| 4 | US20180131579A1 | Systems and interface for remotely managing server operations | 50 |
| 5 | US20210056209A1 | Method, system, and storage medium for security of software components | 38 |
| 6 | US20200394654A1 | Deploying a cloud-based system using a distributed ledger | 31 |
| 7 | US20040177135A1 | Image files constructing tools for cluster configuration | 9 |
| 8 | US20220261804A1 | Deploying a cloud-based system using a distributed ledger | 3 |
| 9 | US11455400B2 | Method, system, and storage medium for security of software components | 3 |
| 10 | US11341503B2 | Deploying a cloud-based system using a distributed ledger | 3 |
Citation counts are drawn from a searched corpus and skew toward older filings; read them as a signal of influence on later art, not of current commercial relevance.
Each row carries its publication number; clicking a row searches Eureka by that number.
Put your own technology through the same analysis
Eureka on the web
When you want the answer in the next five minutes.
The agent works the prompt against patents and technical literature, citing every source.
Run your analysis now →MCP server & REST API
When it has to run inside your own pipeline.
Patent search, landscape analysis and assignee resolution as MCP tools. Drop them into any agent framework, or call REST directly.
Browse MCP servers →What the numbers mean for a filing decision
Three read-outs from the dataset, useful for deciding where new claims are likely to clear prior art and where they are not.
Filing is concentrated, not distributed
The top 5 assignees hold 61.8% of all 34 records in scope, and the leader alone accounts for 6. A new entrant filing broad detection claims is filing against a small number of well-established portfolios rather than a fragmented field.
Claims cluster in data-processing framing
Nearly four in five records sit in G06F, meaning most inventions are claimed as data-processing methods for scanning, comparing or scoring packages rather than as network-transport or transaction inventions. H04L coverage at 38.2% marks the secondary cluster around transmission and delivery verification.
Activity has already peaked once
The trend rises from zero in 2017 to a high of 6 records in 2023, then tapers into a partial, lag-affected 2025-2026 window. That single peak year, rather than a steady climb, suggests filing has come in a cluster rather than a sustained ramp.
Eureka can read the same corpus for gaps instead of for coverage: under-claimed branches adjacent to malicious package detection in repositories, with the prior art for and against each one.
Who holds the ranked positions, and where the gate sits
The ranking behind this dataset covers 12 companies, counted in records — not a top-50 or top-100 list, but the complete set the data endpoint returns for this search.
One assignee sets the pace
The top-ranked assignee holds 6 of the 34 records in scope, the largest single share in the ranking. That volume alone does not confirm breadth of coverage, but it does mean any new filer needs freedom-to-operate review against this portfolio first.
A tight cluster behind the leader
Fifth place holds 3 records, and the top 5 combined reach 61.8% of all 34 records. The gap between the leader and the rest of the top 5 is real but not enormous, meaning the field is contested rather than dominated by one player alone.
The tail thins out fast past rank ten
Tenth place holds 2 records, and the top 10 combined already reach 94.1% of the field. Beyond rank ten, remaining filers hold single-digit, likely single-filing positions — a sign that late entrants have not yet built portfolio depth here.
| Assignee | Recent year | YoY |
|---|---|---|
| Sonatype Inc | 0 | — |
| American Express Travel Related Services Company, Inc. | 0 | — |
| KARAMBITAI INC | 0 | — |
| Cisco Technology, Inc. | 0 | — |
| Yinwang Intelligent Technologies Co., Ltd. | 0 | -100% |
| DISH WIRELESS LLC | 0 | — |
| SPEKTION INC | 0 | -100% |
| SINGLEHOP LLC | 0 | — |
Where to take this next
The dataset points to a concentrated top, a fast-thinning tail, and a technology mix still weighted toward data-processing framing over network or access-control claims.
Check freedom-to-operate against the top 5
With 61.8% of all 34 records held by five assignees, any new filing in core detection methods should start with a clearance review against that group before drafting claims.
Explore assignee portfolios in EurekaScope claims toward under-claimed branches
Access control, version pinning enforcement and name-similarity scoring show thinner coverage than the core G06F detection cluster, and may offer more room for a defensible first claim.
Run a white space search in EurekaTrack the 2025-2026 window as data settles
Because publication lags filing by roughly 18 months, the apparent slowdown after the 2023 peak is not yet reliable; revisit the trend once later filings publish.
Set a filing alert in EurekaCommon questions on this landscape
This landscape identifies 34 published patent records matching the search criteria for malicious package detection, repository code integrity verification, and related mechanisms like install-script analysis and package signature checking, filed between 2015 and the 2026-07-31 data cut-off. That figure covers the specific combination of detection concepts and mechanisms defined in the search string, not every patent that touches software security broadly. Because publication lags filing by roughly 18 months, the true count for 2025 and 2026 filings is understated in current data.
The ranking behind this dataset covers 12 companies, with the leading assignee holding 6 of the 34 records in scope and the top 5 combined accounting for 61.8% of the field. This is a concentrated but not monopolized space: the top 10 assignees together reach 94.1% of all records, leaving only a small remainder spread across additional filers. Company-level portfolios should be reviewed directly in a patent search tool before drawing firm freedom-to-operate conclusions.
The dominant IPC subclass is G06F, electric digital data processing, covering 79.4% of the 34 records — most inventions here are framed as data-processing methods for scanning, scoring or comparing packages. H04L, digital information transmission, appears in 38.2% of records, reflecting the network-transport and delivery-verification side of the technology. G06Q and H04W are minority classes at 11.8% and 5.9% respectively, tied to commerce-platform and wireless-specific applications. A single record can carry more than one class, so these percentages add up to more than 100% of the record total.
The filing trend rises from zero records in 2017 to a peak of 6 in 2023, then continues into a partial, still-incomplete 2026 count. There are fewer than four complete years of data once the publication lag is factored in, so a reliable growth rate cannot be computed from this trend alone. The safest reading is that filing activity clustered around 2022-2023 rather than following a steady multi-year climb, but recent years may look stronger once late-published applications appear.
Relative to the dense core cluster in G06F data-processing detection claims, sub-areas like install-script behavioral sandboxing, name-similarity scoring for typosquatting, version-pinning enforcement, and repository access-control policy engines show thinner coverage across the 34 records. These are not unclaimed, but they carry less filing density than the core detection methods, which typically means more room for a narrowly drafted first claim rather than an open field. Any filing strategy here should still run a freedom-to-operate check against the top-ranked assignees, who hold the bulk of the broader detection claims.
Research Malicious Package Detection in Repositories in depth with Eureka
Go past this page: query the whole malicious package detection in repositories corpus yourself, in your own scope.
Every answer comes back with patent numbers you can open.
Disclaimer. This page is generated from Patsnap Eureka data drawn from a limited snapshot of global patent and scientific-literature records, and is provided for general information and reference only.
Patent data carries inherent limitations: recent filings (typically the most recent 18–24 months) are under-counted due to standard publication lag; counts may be reported at either a patent-family or a patent-record basis and are not always directly comparable; classification, applicant-name, and citation data may contain errors, duplicates, or omissions; and the underlying search query defines and constrains the scope shown. As a result, the analysis may be incomplete or inaccurate and may not reflect the full technology landscape.
Nothing on this page constitutes an exhaustive prior-art, novelty, freedom-to-operate, or validity search, nor does it constitute legal, financial, investment, or professional advice, and it should not be relied upon as such. Any patent, commercial, or strategic decision should be verified independently and reviewed with qualified patent, legal, and domain professionals. Patsnap makes no warranties, express or implied, as to the accuracy, completeness, or fitness for any particular purpose of the information presented.
Machine translation. Assignee and organisation names originally recorded in Chinese, Japanese or Korean have been rendered into English by an AI translation step so that the tables stay readable. These renderings are best-effort and may not match a company’s registered English name; the original name is what the underlying patent record carries, and it is what any Eureka query launched from this page uses.