Skip to main content

Open Source Research

Threat Intelligence

Open source threat research for the AI security community. Detection patterns, malicious signatures, prompt injection analysis, and community-driven threat intelligence.

55 threat signatures133 known threats17 prompt-injection rulesCommunity-driven

Detection Patterns

55 signatures

Detailed guide to Sigil's detection patterns across all 8 scan phases — from install hooks and code execution to prompt injection and AI skill malware.

Install Hooks

CRITICAL (10x) · 10 rules

Code Execution

HIGH (5x) · 49 rules

Network/Exfiltration

HIGH (3x) · 101 rules

Credentials

MEDIUM (2x) · 37 rules

Obfuscation

HIGH (5x) · 32 rules

Provenance

LOW (1-3x) · 13 heuristics

Prompt Injection

CRITICAL (10x) · 17 rules

AI Skill Security

HIGH (5x) · 9 rules

Explore →

Prompt Injection Patterns

8 attack categories

17 shipped detection rules plus a research catalogue of prompt-injection techniques: direct instruction override, jailbreak personas, credential exfiltration, tool/function abuse, and social engineering.

Direct Instruction Override

Research category

Known Jailbreak Personas

Research category

System Prompt Exfiltration

Research category

Tool/Function Abuse

Research category

Sandbox & Detection Evasion

Research category

Social Engineering

Research category

Encoding-Based Injection

Research category

Multi-Turn Manipulation

Research category

Explore →

Malicious Signatures Database

133 known threats

Curated database of 133 known threats across 18 tracked campaigns and 55 detection signatures, each with detection rationale. Hash-based lookups and campaign attribution.

Explore →

Tracked Malware Families

Shai-Hulud npm Worm

Sep 2025

Self-propagating install hooks that modify package.json of infected projects

2.6B+ weekly downloads affected

MUT-8694 Cross-Ecosystem

Oct 2024

Binary delivery via provenance metadata abuse across two registries

Coordinated npm + PyPI campaign

Hugging Face Model Poisoning

Feb 2024

Pickle deserialization exploit embedded in model weights

100+ ML models with reverse shells

Contribute

Help improve AI security by contributing signatures, reporting false positives, or sharing threat intelligence. Sigil's detection patterns are open source and community-audited.

Report Threats

Submit new malware samples or suspicious packages for analysis.

Contribute Signatures

Add detection patterns via pull request to the open-source repo.

Report False Positives

Help reduce noise by reporting false positives in detection rules.