/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

VirusTotal launches Monitor aimed at helping developers mitigate false positives by letting them upload and scan new code against their 70+ antivirus partners

Frederic Lardinois / TechCrunch :

TechCrunch Frederic Lardinois

Context & Ripple Effects

Monitor extends VirusTotal beyond its role as a reactive malware-scanning aggregator — it had already added sandbox execution support for Mac OS X apps in 2015 — into a pre-release workflow tool where developers upload new code and see how 70+ antivirus engines flag it before shipping.

The move matters because false positives are a two-sided failure: users lose software they trust, and antivirus vendors burn reputation on bad detections. Months later, Alphabet's Chronicle turned the same corpus into a paid product with VirusTotal Enterprise, signaling that Google saw this data as a business line, not just a free utility.

First-order effects

  • Developers gain a direct feedback loop with the 70+ antivirus partners before release, letting them dispute or fix detections that would otherwise block installs at launch.
  • Antivirus vendors get earlier visibility into new binaries, shifting some false-positive resolution from post-release user complaints to pre-release triage.

Second-order effects

  • Pre-release scanning platforms start competing with adjacent security tooling — GitHub's later rollout of its own code-scanning tool shows the same 'catch problems before public deployment' wedge being contested by bigger developer-platform players.

Third-order effects

  • The pattern points toward threat-intelligence aggregators becoming default infrastructure for software distribution itself: by 2026, OpenClaw was routing every skill published to its ClawHub marketplace through VirusTotal's threat intelligence, making one company's corpus a de facto gatekeeper for third-party code.
  • That gatekeeping position also creates a dependency risk for smaller developers, since access to the shared virus corpus becomes something vendors can condition rather than assume.

The trend: Malware-scanning aggregators are evolving from free reactive utilities into paid, pre-release infrastructure that sits inside the software supply chain between developers and their users.