What are the essential features of Kaspersky Threat Data Feeds Open Source Threats?
No console – Subscription data feed, no agent or dashboard.
JSON delivery – Machine-readable records for automated matching in pipelines.
Eight repositories – PyPI, npm, NuGet, Maven, Composer, Go, RPM, Debian.
Threat types – Vulnerable, malicious, riskware and politically compromised packages.
Binary-less data – No executable code enters your build environment.
Important note – You supply the matching tool or SCA scanner.
Open source package records – Entries for known malicious, compromised and vulnerable packages.
Eight package repositories – PyPI, npm, NuGet, Maven, Composer, Go, RPM and Debian.
Advisory cross-links – GitHub Security Advisory, CVE MITRE, Debian and CentOS alerts.
Version and fix context – Vulnerable version lists, CPE strings and recommended patched versions.
Malware package context – Severity, system impact, CWE and hashes of compromised versions.
Important – No management console, no agent and no scanning engine included.
Kaspersky Threat Data Feeds Open Source Threats is the retail name for the Kaspersky Open Source Software Threats Data Feed, one of more than 25 feeds in the Kaspersky Threat Data Feeds line. It has no management model of its own: you subscribe to a JSON data set and match it against your own dependency inventory with your own tooling.
Dependency screening – Flags risky packages before they reach a production build.
Four-hour updates – The feed is refreshed every four hours by Kaspersky.
No binaries – Text-only records, so nothing executable enters your build servers.
Beyond CVE data – Covers deliberately malicious and politically altered packages, not just vulnerabilities.
Automation-ready output – JSON with CPE strings for scripted matching in CI pipelines.
Exploit hashes – Hashes of exploits seen in the wild for prioritisation.
Company size is the wrong filter for this product. The deciding question is whether your organisation writes software that pulls in third-party open source packages, and whether you already run a tool that can match a JSON package list against your dependency inventory. A company of 30 developers gets more out of this feed than a company of 800 office workers who only buy finished software.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | If supplier | ✓ | ✓ |
| Own build pipeline and matching tools | ✕ | Sometimes | ✓ |
| This product fits | ✕ | With DevSecOps | ✓ |
The reporting duty under the revised Information Security Act applies to operators of critical infrastructure, not to companies in general, and it is triggered by sector and role rather than by headcount. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. This feed supports one narrow part of that picture: it tells you which open source packages in your own software are known to be malicious, compromised or vulnerable, which is exactly the detail a report needs when the entry point was a poisoned dependency. It does not detect the attack, does not monitor your network, does not keep logs, and produces no report you could submit, so the 24-hour clock is still handled by your monitoring and incident process, not by this subscription. It also says nothing about your own source code, only about third-party packages you pull in. This text is not legal advice, and whether your organisation falls under the reporting obligation should be assessed with your own legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational measures and processes rather than tooling. NIS 2 requires risk analysis and security policies, incident handling, business continuity, supply chain security, security in the acquisition, development and maintenance of network and information systems including vulnerability handling, cyber hygiene and training, access control, and cryptography. This feed maps onto two of those categories: supply chain security, by naming third-party packages that carry known threats, and vulnerability handling during development, by supplying vulnerable version ranges, CPE strings and recommended patched versions. It contributes nothing to incident handling, business continuity, access control, multi-factor authentication, staff training, cryptography or endpoint protection, and it generates no policy documentation. Treat it as one input into a development-security process that has to exist independently of it.
Two official measures are in force and both are worth knowing before a purchase. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky virus protection software since 15 March 2022 and still publishes that warning; following the German act implementing the NIS 2 Directive, which took effect on 6 December 2025, it now sits under Section 13 BSIG. The BSI states that the warning concerns virus protection software from the Kaspersky portfolio and that it made no statement about other products, which is a material distinction for a text-only data feed. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from providing antivirus software and cybersecurity products or services to US persons, in force since 29 September 2024, and added AO Kaspersky Lab together with two further entities to the Entity List. Switzerland has taken a different line: BACS has issued no warning and no internal directive on Kaspersky software, stated that its technical assessment was not changed by the US ban, and said it would inform the public if it obtained evidence of misuse. Kaspersky rejects the BSI warning as not based on an objective technical risk analysis, points to its data centres in Switzerland, and in early 2026 asked the BSI to withdraw the warning while reserving legal steps. On testing, note that the independent comparative laboratories assess Kaspersky endpoint products, not this data feed, so no test score can be transferred to it either way. In practice this matters most for public sector tenders, suppliers to German federal bodies, and anyone whose contracts or customer supply chain clauses restrict software of Russian origin; for other buyers the relevant technical fact is that the feed ships no executable code and runs no process on your systems.
Yes, but only for one block of questions. It gives you a defensible answer to items on third-party component screening, on how you identify vulnerable and malicious open source dependencies, and on whether your checks go beyond published CVE lists, since the feed also flags deliberately malicious packages, riskware and packages altered for political reasons. It answers nothing about endpoint protection, EDR, patch management of operating systems, encryption, multi-factor authentication, backup and restore, access control, logging retention, awareness training, incident response, penetration testing or certifications. It also produces no evidence document by itself: the audit trail a customer wants to see has to come from the reports of the tool that consumes the feed, which is the point most buyers underestimate. To close the largest gaps at the lowest cost, stay inside the same vendor family before mixing suppliers: endpoint and EDR questions are covered by the Kaspersky Next line, and SIEM-side matching and alert context by Kaspersky CyberTrace or the Kaspersky Unified Monitoring and Analysis Platform.
The decisive difference is where the data is matched: the Open Source Threats feed is matched against your dependency list inside the build process, while the network security feeds are matched against traffic and events at the perimeter and in the SIEM. That difference drives everything else, including the data type, the delivery format and the update rhythm. Both are subscriptions to data rather than software, and neither blocks anything on its own. Buying one does not cover the use case of the other, so development teams and security operations teams usually need different feeds from the same line.
| Property | Open Source Threats | Network security feeds |
|---|---|---|
| Data listed | Software packages | URLs, hashes, IPs |
| Main use case | Build pipeline | SIEM and firewall |
| Delivery format | JSON | JSON, CSV, OpenIoC, STIX |
| Feeds an NGFW deny list | ✕ | ✓ |
| Update interval | Every 4 hours | From 20 minutes |
Regional availability is the first limitation to check: under the US Final Determination of June 2024, Kaspersky may not supply cybersecurity products or services in the United States or to US persons, in force since 29 September 2024, so US entities and US-based subsidiaries are outside the addressable market for this subscription. The second limitation causes most follow-up purchases: the feed is data only, Kaspersky performs no matching, and you need either an existing software component analysis tool that can ingest a JSON package list or the development effort to build that matching yourself. Repository coverage is limited to the eight published repositories, so packages from crates.io, RubyGems, Conda or container image registries are not covered, although Kaspersky states that further repositories can be added as they gain popularity. Finally, the scope is third-party open source packages only: your own source code, commercial third-party libraries and misconfigurations in your infrastructure are outside what this feed can tell you, and it protects no endpoint, server or mailbox.
No. It is a data source designed to be consumed by such a tool or by your own scripts. Kaspersky supplies the package records and the context; identifying which of those packages appear in your projects is done by your tooling, matched on parameters such as package name and version.
Yes. Alongside PyPI, npm, NuGet, Maven, Composer and Go, the feed scans RPM and Debian repositories, and it records supported operating system versions for these packages. Findings are cross-linked to Debian Security Advisory, CentOS Security Alerts and Red Hat Security Advisory entries.
The Kaspersky Threat Data Feeds line integrates with SIEM and threat intelligence platforms including IBM QRadar, Splunk Enterprise Security, ArcSight ESM, Azure Sentinel and MISP, usually through Kaspersky CyberTrace. Package findings are still most useful at build time, because a SIEM has no view of which dependencies a project declares.