Deals · Cybersecurity
Ossprey raises $2.65M to scan open-source packages for malicious code before it reaches production
A UK cybersecurity startup continuously scanning open-source packages for malicious code before it reaches production — purpose-built for the speed at which AI-assisted engineering teams now ship software.
“We founded Ossprey because existing approaches weren't designed for the pace modern engineering teams now operate at. Organisations shouldn't have to choose between shipping software quickly and building it securely. This investment allows us to continue developing technology that helps organisations build safely at AI speed while expanding our reach internationally.”
Ossprey, a UK cybersecurity startup founded in 2024 by Nate Dunning (CEO) and David Read, has raised an oversubscribed $2.65 million / €2.41 million pre-seed round led by Episode 1 Ventures, with participation from Osney Capital and Octopus Ventures. The company builds continuous scanning technology for open-source software packages, designed to catch malicious code before it reaches production environments.
The round closed oversubscribed — an unusual position for a pre-seed — signalling investor demand ahead of a market problem that has moved quickly from specialist concern to boardroom risk. The oversubscription is a data point on investor conviction, not a proof of product traction; Ossprey is still at the stage of building and proving out the detection technology.
The supply chain attack surface
Roughly 90% of enterprise software today is built on open-source packages — libraries, frameworks, and utilities that developers pull from public registries. That dependency is also the attack surface. Supply chain attacks work by compromising or impersonating legitimate packages so that consuming teams pull malicious code into their builds without realising it. The pattern has produced some of the most damaging security incidents of the past several years: dependency confusion attacks, typosquatting, and the injection of backdoors into widely-used packages weeks or months before discovery.
Current security tooling addresses an earlier era of software development: it was designed for a cadence where a human reviews a dependency before it ships, where dependency updates happen in deliberate cycles, and where the build pipeline is slow enough to add a security gate without breaking developer flow. AI-assisted development has changed each of those assumptions. Pull requests move faster, dependency updates are more frequent, and the review window has compressed to near-zero. A security tool that requires human review at each step doesn't fit the speed at which engineering teams now operate.
"We founded Ossprey because existing approaches weren't designed for the pace modern engineering teams now operate at," said Nate Dunning, CEO. "Organisations shouldn't have to choose between shipping software quickly and building it securely. This investment allows us to continue developing technology that helps organisations build safely at AI speed while expanding our reach internationally."
What Episode 1 backed
The Episode 1 Ventures lead reflects that firm's consistent positioning in cybersecurity infrastructure for developer and engineering workflows — an area where the combination of AI-accelerated development and supply chain threat has created a visible product gap. Osney Capital and Octopus Ventures round out a syndicate that spans specialist security investing and broader venture.
The $2.65 million pre-seed funds continued development of Ossprey's core scanning technology and international expansion. The two tests the capital must answer: whether continuous automated scanning catches novel malicious packages that current tools miss, and whether it integrates with fast-moving development pipelines without adding friction that causes engineering teams to route around it. Detection accuracy and developer adoption are both necessary; either alone doesn't close the gap the company was founded to address.
Sources
Threaded to this story
Cybersecurity ·
Xentra raises £2.7M to scale managed cybersecurity for UK SMEs
€3.2M
Cybersecurity ·
Prague's Wultra raises €6.8M Series A to ready bank logins for the quantum era and the EU identity wallet
€6.8M · Series A
Cybersecurity ·
MokN raises €12.9M Series A — and lands GV's first cheque into a French startup
€12.9M · Series A
Every European round, in your inbox by 8am.
The day's seed and Series A rounds across France and Europe — threaded, sourced, and read in two minutes. Free.