Open Source Research
Threat Intelligence
Open source threat research for the AI security community. Detection patterns, malicious signatures, prompt injection analysis, and community-driven threat intelligence.
Detection Patterns
55 signaturesDetailed guide to Sigil's detection patterns across all 8 scan phases — from install hooks and code execution to prompt injection and AI skill malware.
Install Hooks
CRITICAL (10x) · 10 rules
Code Execution
HIGH (5x) · 49 rules
Network/Exfiltration
HIGH (3x) · 101 rules
Credentials
MEDIUM (2x) · 37 rules
Obfuscation
HIGH (5x) · 32 rules
Provenance
LOW (1-3x) · 13 heuristics
Prompt Injection
CRITICAL (10x) · 17 rules
AI Skill Security
HIGH (5x) · 9 rules
Prompt Injection Patterns
8 attack categories17 shipped detection rules plus a research catalogue of prompt-injection techniques: direct instruction override, jailbreak personas, credential exfiltration, tool/function abuse, and social engineering.
Direct Instruction Override
Research category
Known Jailbreak Personas
Research category
System Prompt Exfiltration
Research category
Tool/Function Abuse
Research category
Sandbox & Detection Evasion
Research category
Social Engineering
Research category
Encoding-Based Injection
Research category
Multi-Turn Manipulation
Research category
Malicious Signatures Database
133 known threatsCurated database of 133 known threats across 18 tracked campaigns and 55 detection signatures, each with detection rationale. Hash-based lookups and campaign attribution.
Explore →Tracked Malware Families
Shai-Hulud npm Worm
Sep 2025Self-propagating install hooks that modify package.json of infected projects
2.6B+ weekly downloads affected
MUT-8694 Cross-Ecosystem
Oct 2024Binary delivery via provenance metadata abuse across two registries
Coordinated npm + PyPI campaign
Hugging Face Model Poisoning
Feb 2024Pickle deserialization exploit embedded in model weights
100+ ML models with reverse shells
Contribute
Help improve AI security by contributing signatures, reporting false positives, or sharing threat intelligence. Sigil's detection patterns are open source and community-audited.
Report Threats
Submit new malware samples or suspicious packages for analysis.
Contribute Signatures
Add detection patterns via pull request to the open-source repo.
Report False Positives
Help reduce noise by reporting false positives in detection rules.