Overview
The average enterprise runs on code nobody on the team wrote. Nobody writes everything from scratch anymore, and nobody should have to. But that reliance has created an opening, and attackers have noticed. Instead of breaking through firewalls or exploiting zero-days, they're publishing malicious packages under trusted names and waiting for developers to pull them in through normal, everyday workflows.
That's the problem we started Ossprey to solve. Today we're announcing $2.65 million in pre-seed funding, led by Episode 1 Ventures, with Osney Capital and Octopus Investments also participating. The round was oversubscribed, and it's one of the largest pre-seed raises by a UK cybersecurity company to date.
We didn't set out to build another scanner that flags known vulnerabilities after the fact. Signature-based tools can tell you a package matches something already catalogued as bad. They can't tell you a package is malicious the first time it appears, before anyone has had the chance to document it. That gap is exactly where modern software supply chain attacks live, and it's growing. A CVE describes a weakness that might one day be exploited. A malicious package is the exploit, already running the moment it's installed. Tooling can treat those two things as the same problem, which is why so much slips through.
AI coding assistants have changed the pace of software development. Teams ship more code, faster, and a growing share of it comes from packages nobody on the team has personally reviewed. Some people call this "vibe coding." No matter the name, the volume of dependencies flowing into production has gone up sharply, and it keeps climbing. That's the environment we built Ossprey for.
Ossprey continuously scans open source packages across major ecosystems and flags malicious code before it reaches a developer's machine, not after it's already shipped. We've built the platform to run at the speed engineering teams actually operate at now, not the speed security tooling assumed a decade ago. Since closing this round, we've grown to seven people, expanded the platform, and launched public scanning that's already identifying newly published malicious packages faster than most of the industry manages.
"Software development has fundamentally changed," said Nate Dunning, our CEO. "AI is enabling organisations to build software faster than ever before, but it's also dramatically increasing the amount of code entering production and creating new opportunities for attackers to hide malicious software inside trusted open source packages. We founded Ossprey because existing approaches weren't designed for the pace modern engineering teams now operate at."
That's the trade-off we're trying to remove. Security teams shouldn't have to slow engineering down to catch what's hiding in a dependency tree, and engineering teams shouldn't have to accept risk just to ship on schedule. Millan Suri, Principal at Episode 1, put it plainly: "our detection engine catches what signature-based tools miss, and it does that because the team behind it has actually lived the problem from the inside."
We're not chasing a broad security category. Our focus is narrow: catch malicious code before it hits production, and do it without adding friction for the people writing the software. Everything else- the dashboards, the integrations, the reporting, everything else exists to support that one job.
There's more coming. We're planning another funding round within the next year, and the near-term plan is straightforward: keep growing across the UK, then push into Europe and North America, with a particular focus on organisations building software at enterprise scale. If your team is shipping fast and pulling in open source dependencies without a way to check what's actually inside them, you can try it for yourself with our 30-day free Early Bird Programme.




