This article covers Ossprey, a cybersecurity startup, which has raised £2m in a pre-seed funding round to detect malicious open source packages before they reach production. The development supports enterprise engineering teams by scanning third-party packages to flag malicious code early and address software supply chain risk.
Ossprey, a cybersecurity startup, has raised £2m in a pre-seed funding round to detect malicious open source packages before they reach production. The round was led by Episode 1 Ventures, with participation from Osney Capital and Octopus Investments, and comes as enterprises face a rising tide of supply chain attacks amplified by faster development workflows and AI coding assistants.
Attackers are increasingly delivering malicious code by publishing packages under trusted names rather than exploiting traditional vulnerabilities. That means signature-based scanners, which look for known bad indicators, can miss novel malicious packages the first time they appear. As engineering teams ship code faster and pull in more third-party dependencies, the window for undetected compromise widens.
Ossprey’s raise is notable in context: at £2m it ranks among the larger pre-seed rounds for a UK cybersecurity company, signalling investor appetite for tools that address software supply chain risk at development speed.
Ossprey says its platform continuously scans open source packages across major ecosystems and flags malicious code before it reaches a developer’s machine, rather than after deployment. The company emphasises low friction for engineering teams: the detection runs at the pace of modern development workflows and integrates with existing tools and reporting systems.
Since closing the round Ossprey has grown to seven staff, expanded the platform and launched public scanning that the company claims identifies newly published malicious packages faster than most existing services. It also offers a 30-day Early Bird programme for teams to trial the scanning service.
Episode 1 Ventures led the round, with Osney Capital and Octopus Investments participating. The round was oversubscribed, according to the announcement.
Episode 1 Ventures is an early-stage investor focused on developer and infrastructure technologies; Osney Capital and Octopus Investments are established UK investors that back growth in enterprise and tech firms. The investors cited the team’s operational experience and the product’s approach to detecting previously unseen threats as reasons to back Ossprey.
In the announcement, Millan Suri, Principal at Episode 1, said:
our detection engine catches what signature-based tools miss, and it does that because the team behind it has actually lived the problem from the inside.
If you're researching potential backers in this space:
In the announcement, Nate Dunning, CEO at Ossprey, said:
Software development has fundamentally changed. AI is enabling organisations to build software faster than ever before, but it's also dramatically increasing the amount of code entering production and creating new opportunities for attackers to hide malicious software inside trusted open source packages. We founded Ossprey because existing approaches weren't designed for the pace modern engineering teams now operate at. The company frames its mission as removing the trade-off between speed and safety: security teams should not have to slow engineering to catch malicious dependencies, and engineering teams should not accept risk to meet delivery schedules. Ossprey plans another funding round within the next year, with near-term expansion priorities across the UK, then into Europe and North America, targeting organisations building software at enterprise scale.
Software supply chain attacks have moved up the security agenda for enterprises and policymakers alike. The growth of AI coding assistants and faster release cadences increases reliance on third-party packages, which in turn creates more opportunities for attackers to hide malicious behaviour in code that appears trustworthy.
The Ossprey raise adds to a string of funding and product announcements aimed at supply chain protection, and it reflects growing interest from cybersecurity investors in tooling that operates at developer speed. For UK and European organisations that build and ship software rapidly, the problem Ossprey targets is becoming part of standard security planning rather than a niche concern.
The funding underscores a broader shift in the ecosystem: defenders are investing earlier in developer-focused security controls as part of a push to prevent malicious code from entering production in the first place.
| Investors | Investment Focus | Startup Investments | Round Size | Connect |
|---|---|---|---|---|
![]() Episode 1 Ventures( ) The firm specialises in investing in Pre-Seed and Seed stage B2B software compan... London | ||||
![]() Osney Capital( ) Osney Capital is a venture capital firm specialising in the early-stage Cyber se... London | ||||
![]() Octopus Ventures( ) This venture capital firm focuses on investing in sectors such as B2B Software, ... London | ||||
| All investors | All investor sectors | All funded startups | All funding rounds |
Click here for a full list of 7,589+ startup investors in the UK