The install-time supply-chain firewall

Your software is built from strangers' code. We keep the malware out.

A firewall in front of every npm, PyPI, Go and NuGet install on your laptops, CI runners and servers, including the installs AI coding agents run. It stops malicious packages before they run.

No card needed · from $25 per developer a month

BLOCKaxios 1.14.1

Hijacked release: remote-access trojan. Upgrade to 1.20.0.

fig. 01 / every package your machines install passes one checkpoint
Public registries
npmregistry.npmjs.org
PyPIpypi.org
Goproxy.golang.org
NuGetnuget.org
BLOCKaxios 1.14.1

Hijacked release: remote-access trojan.

Stopped at the proxy. It never reached the pipeline.

Upgrade to 1.20.0

CyberXYZ Proxyevery install passes here
Your company
Developer laptopsmacOSWindowsLinuxALLOW
requirements.txtrequests 2.32.5
CI/CD pipelinesGitHub ActionsGitLabJenkinsNever arrived
package.jsonaxios 1.14.1
ServersLinuxWindowsALLOW
go.modgithub.com/google/uuid v1.6.0
AI coding agentson your machinesALLOW
.csprojNewtonsoft.Json 13.0.3

Packages arrive from the files your projects already use (package.json, requirements.txt, go.mod, .csproj and their lockfiles), plus every dependency they pull in that nobody on your team picked. It covers every laptop, server and pipeline where it is turned on, and each decision is logged in CyberXYZ Dashboard. Verdicts are real for these exact versions; the places are examples.Packages arrive from the files your projects already use, lockfiles and every dependency included. It covers every machine and pipeline where it is turned on, and each decision is logged. Verdicts are real for these exact versions; the places are examples.

BLOCK Fake AI libraries on PyPI, 11 Sep 2026Blocked 34 minutes after they were published, 2 h 46 min before the public advisory.One of our earliest catches. Most malware is blocked once an advisory lists it. How we measure
  • 240K+known malicious packages and extensions
  • 46M+package releases tracked
  • 11M+dependency links mapped

Counts from the CyberXYZ database, 7 Oct 2026. Releases cover five registries.

Working with security teams at

Accenture AthenaGuard Network International Etuteki Lab SichGate
How it works

Three steps.
No new habits.

  1. 1

    Turn it on once

    One setup step on each laptop, server and CI pipeline points npm, pip, Go and NuGet at CyberXYZ Proxy. After that nothing changes: the same projects, the same files, the same pipelines. AI coding agents on those machines are covered too.

    On a laptop
    $ xyz proxy setup
    Across a fleet (MDM)
    $ sudo xyz proxy setup --system
    In CI
    $ eval "$(xyz ci protect)"
    • Install the CLI with pipx install cyberxyz-scanner, then run xyz login.
    • On GitHub Actions, use CyberXYZSecurity/depalert-action@v1.
    • Covers npm, pnpm, yarn, bun, pip, uv, Go and NuGet.
    app.cyberxyz.io · Proxy services
    CyberXYZ Dashboard, Proxy services panel: the npm, PyPI, Go and NuGet proxy endpoints all show ONLINE under "All responding", and the enforcement row reads "Enforcing: risky installs are blocked".
    The same onmacOSWindowsLinuxGitHub ActionsGitLabJenkinsAzure DevOps
  2. 2

    We read it before it lands

    CyberXYZ checks every package before it lands: its code, the new dependencies it brings and its release history. If it finds malware, the install stops.

    axios@1.14.1BLOCK
    why
    A hijacked maintainer account added plain-crypto-js, a brand-new dependency that installs a remote-access trojan

    Six checks on every install; three fired for axios@1.14.1

    New dependency Odd version jump (fired) Known malware (fired) Security advisory (fired) Commit-level review Vendor breach
    ALLOW
    The install goes ahead and is logged.
    ALERT
    The install goes ahead. The reason shows in your dashboard.
    QUARANTINE
    Stopped and held for review: early warning signs, no advisory yet.
    BLOCK
    Refused: a known malicious version, a critical advisory, or your org's block list.
  3. 3

    Your team hears about it

    Safe packages install normally. Blocked ones never reach the machine, and the reason shows up where your team already works: the dashboard, the pipeline, the editor and the terminal.

    app.cyberxyz.io · Proxy monitor, last 7 days
    CyberXYZ Dashboard, Proxy monitor: a bar chart of the most-blocked packages over the last 7 days, counting blocked install attempts with all versions of a package added together. python-jose leads with 5; colors, eslint-scope, event-stream and faker have 2 each; anyio, axios and h11 have 1 each.
    BLOCKInstall blocked
    packageaxios 1.14.1 wherea CI/CD pipeline

    Where your team sees it

    • Dashboard
    • GitHub Actions
    • GitLab CI
    • Azure DevOps
    • VS Code
    • Your terminal
Why it matters

1 package becomes 66

You ask for one package. You get dozens.

Adding express, one of the most popular web frameworks, quietly brings in 65 more packages. Any one of them can be hijacked, and the malware arrives with the package you chose.

Fresh install of express 5.2.1 on 7 Oct 2026. npm reports "added 68 packages" because it installs one of the 66 in three places. Maintainer accounts from the npm registry.

fig. 02 / one package asked for, 66 checkedfig. 02 / 1 asked for, 66 checkednpm · 7 Oct 2026

Your project asks for one package.

package.json"express": "^5.2.1" express 5.2.1ALLOWyou chose this

The same whether a laptop or a CI runner installs it.

It quietly brings in 65 more.

ALLOW today: 64ALERT today: 1 (router 2.2.0, a new dependency in this release)

maintained by 34 npm accounts outside your company · up to 6 levels deep

One of them went bad.

debug 4.4.2Publisher's account phished, malware addedBLOCK

A fresh express install that day could pull it in. npm pulled it later that day, and this time the malware only attacked browsers.

Today express installs debug 4.4.3: ALLOW.

CyberXYZ checks all 66, not only the one you chose.
Today's express install:ALLOW65ALERT1· nothing to block
Caught in the wild

We don't theorize about attacks.
We catch them.

Real campaigns, each written up in full: the timeline, the signals that fired and what we changed afterwards, including the one we missed.

fig. 03 / one attack, minute by minutePyPI · 11 Sep 2026 · times in UTC

Fake AI libraries on PyPI

openaii, langgrap, ollamaa and transfomers: copies of openai, langgraph, ollama and transformers that hid code which runs every time Python starts.

34 minfrom publish to block
3 h 20 minfrom publish to the advisory
Advisory-based toolsblock once an advisory exists
exposed for at least 3 h 20 min blocked
CyberXYZ: blocked 34 min after publishreads the package itself
34 min blocked at the proxy from 18:13, 2 h 46 min before the advisoryblocked at the proxy from 18:13
  1. published to PyPI
  2. CyberXYZ finds the hidden startup hook
  3. blocked at the proxy BLOCK
  4. public advisory (OSV)

More attacks we caught before the advisory

dotenv-asyncnpm · 30 Sep 2026

A fake dotenv library. Flagged as malware 2 h 57 min after it was published.

4 daysbefore the advisory
Hades, the Shai-Hulud worm on PyPIPyPI · 5 Jun 2026

Customers alerted 30 minutes after the wave began.

6 h 28 minbefore the first OSV record

Selected cases, not the norm: most malicious releases reach CyberXYZ through public advisories, and the proxy blocks them once they are listed. Times come from CyberXYZ block and alert records and the OSV API, checked 7 Oct 2026. Advisory-based tools need at least until the advisory, plus their own update time.

See every attack we caught
How we catch them

We read the code,
not just the scorecard.

Most supply-chain tools rate a package on project-health signals. CyberXYZ does that and reads the code itself. For widely used packages it also reads the commits behind each release, so a malicious hook can be caught in the change, not only after an advisory exists.

sample chore: tidy build scripts illustration
package.json
31 "scripts": {
32- "build": "tsc"
32+ "build": "tsc",
33+ "postinstall": "node ./.cache/setup.js"
The pattern we flag: a lifecycle hook slipped into a "tidy" commit. The script it runs decodes a hidden payload and sends the npm token and environment to an outside server.
34 }
Where it protects you

One firewall.
Everywhere code gets installed.

CyberXYZ Proxy

Sits between your machines and the registries. Every install is checked, and a bad package gets a hard block.

How the proxy works

CI gate

One line in CI. A malicious dependency fails the build before it ever merges.

Add it to CI

CyberXYZ for VS Code

Risky dependencies are underlined as you type, with the full verdict one hover away.

The extension

CyberXYZ CLI

Audit any project and fix what it finds, from your terminal, across npm, PyPI, Go and NuGet.

The CLI

AI models

Checks Hugging Face models and every package they pull in, without ever running the model's code.

Why models need it

CyberXYZ Dashboard

Every install decision, by machine and pipeline, in one place your security team can review.

The dashboard
trusted & built with

Built with the industry's best.

“I really liked the product, and that you’re ahead of the market: commit and PR-level review that catches zero-days before a CVE. We invited the team to present to our incident response and offensive security groups.”

Mansoor HaqaneeCybersecurity Manager, KPMG LinkedIn profile of Mansoor Haqanee (opens in a new tab)
Microsoft GitHub GitLab SentinelOne Elastic Harness Red Hat IBM
AICPA SOC
// compliance

Evidence for your SOC 2 audit, as a side effect.

Every install decision is logged: the package, the machine, the verdict and the reason. That record supports the system-monitoring (CC7.1) and change-management (CC8.1) controls your auditor tests.

// rolling it out

Questions your platform team will ask.

Straight answers from how the product works today.

What happens if CyberXYZ goes down?

If the proxy can’t reach CyberXYZ, it reuses any verdict it already reached for that exact package version in the last 24 hours. Otherwise your organization’s setting decides. By default the install is refused with a “retry in a minute” message. Admins can choose to let unchecked installs through instead.

What do you record about each install?

Each install is logged under your organization with the package, version, verdict and reasons, plus the machine, IP address and package manager. Package files are never uploaded to the CyberXYZ API. Downloads do pass through our hosted proxy on their way from the public registry. If someone asks for a package name the public registry doesn’t have, we keep that name, with the machine that asked, for 90 days after the last request, because missing names are how slopsquatting starts. If someone later registers that name and it becomes an open slopsquatting finding, we keep the record as evidence for up to a year.

Can we set our own rules?

Yes. Org admins can block packages for the whole organization or for single machines, with an optional expiry, and choose the enforcement level and what happens during an outage. Every change goes into your organization’s audit log.

Which machines and pipelines does it support?

macOS, Linux and Windows. Your MDM can enroll a whole fleet with one setup command and your organization’s enrollment token. Pipelines run on GitHub Actions, GitLab CI, Azure DevOps and any other CI that runs a shell.

How do we take it off a machine?

Run xyz proxy remove, or sudo xyz proxy remove on managed machines. It puts each package manager back on its default registry and removes the background agent.

Do we need a credit card to try it?

No. You sign up with your work email and your organization’s name. Each sign-up gets its own private workspace, with you as its admin.

// book a demo

Watch it block a real attack. Then run it on your own installs.

Book 15 minutes. We run real packages through CyberXYZ while you watch, including axios 1.14.1, a hijacked release that dropped remote-control malware in March 2026, and show you exactly what your team would see. Then we connect one laptop or one pipeline for a 30-day proof of value.

What happens next

  1. 01A 15-minute callReal packages, real verdicts, and your questions.
  2. 02Connect one laptop or one pipelineOne setup command, or one line in CI. Under an hour.
  3. 03A 30-day proof of value on your own installsEvery signal, no card.

Not ready for a call?

Check any package, free, and see the verdict we would give it.

npm

Try faker@6.6.6ua-parser-js@0.7.29express@4.21.2

Thanks! We'll be in touch.

Check your inbox. We'll reach out within 24 hours.

Where should we send the invite?

  • 15 minutes
  • Video call
  • Times in your time zone

We reply within 24 hours to set a time.

We only use these details to arrange the call. Privacy policy