A firewall in front of every npm, PyPI, Go and NuGet install on your laptops, CI runners and servers, including the installs AI coding agents run. It stops malicious packages before they run.
No card needed · from $25 per developer a month
axios 1.14.1Hijacked release: remote-access trojan. Upgrade to 1.20.0.
Hijacked release: remote-access trojan.
Stopped at the proxy. It never reached the pipeline.
Upgrade to 1.20.0
requests 2.32.5axios 1.14.1github.com/google/uuid v1.6.0Newtonsoft.Json 13.0.3Packages arrive from the files your projects already use (package.json, requirements.txt, go.mod, .csproj and their lockfiles), plus every dependency they pull in that nobody on your team picked. It covers every laptop, server and pipeline where it is turned on, and each decision is logged in CyberXYZ Dashboard. Verdicts are real for these exact versions; the places are examples.Packages arrive from the files your projects already use, lockfiles and every dependency included. It covers every machine and pipeline where it is turned on, and each decision is logged. Verdicts are real for these exact versions; the places are examples.
Counts from the CyberXYZ database, 7 Oct 2026. Releases cover five registries.
Working with security teams at
One setup step on each laptop, server and CI pipeline points npm, pip, Go and NuGet at CyberXYZ Proxy. After that nothing changes: the same projects, the same files, the same pipelines. AI coding agents on those machines are covered too.
$ xyz proxy setup$ sudo xyz proxy setup --system$ eval "$(xyz ci protect)"
CyberXYZ checks every package before it lands: its code, the new dependencies it brings and its release history. If it finds malware, the install stops.
Six checks on every install; three fired for axios@1.14.1
Safe packages install normally. Blocked ones never reach the machine, and the reason shows up where your team already works: the dashboard, the pipeline, the editor and the terminal.
Where your team sees it
1 package becomes 66
Adding express, one of the most popular web frameworks, quietly brings in 65 more packages. Any one of them can be hijacked, and the malware arrives with the package you chose.
Fresh install of express 5.2.1 on 7 Oct 2026. npm reports "added 68 packages" because it installs one of the 66 in three places. Maintainer accounts from the npm registry.
"express": "^5.2.1"
The same whether a laptop or a CI runner installs it.
ALLOW today: 64ALERT today: 1 (router 2.2.0, a new dependency in this release)
maintained by 34 npm accounts outside your company · up to 6 levels deep
A fresh express install that day could pull it in. npm pulled it later that day, and this time the malware only attacked browsers.
Today express installs debug 4.4.3: ALLOW.
Real campaigns, each written up in full: the timeline, the signals that fired and what we changed afterwards, including the one we missed.
openaii, langgrap, ollamaa and transfomers: copies of openai, langgraph, ollama and transformers that hid code which runs every time Python starts.
A fake dotenv library. Flagged as malware 2 h 57 min after it was published.
Customers alerted 30 minutes after the wave began.
Selected cases, not the norm: most malicious releases reach CyberXYZ through public advisories, and the proxy blocks them once they are listed. Times come from CyberXYZ block and alert records and the OSV API, checked 7 Oct 2026. Advisory-based tools need at least until the advisory, plus their own update time.
Most supply-chain tools rate a package on project-health signals. CyberXYZ does that and reads the code itself. For widely used packages it also reads the commits behind each release, so a malicious hook can be caught in the change, not only after an advisory exists.
Sits between your machines and the registries. Every install is checked, and a bad package gets a hard block.
How the proxy worksOne line in CI. A malicious dependency fails the build before it ever merges.
Add it to CIRisky dependencies are underlined as you type, with the full verdict one hover away.
The extensionAudit any project and fix what it finds, from your terminal, across npm, PyPI, Go and NuGet.
The CLIChecks Hugging Face models and every package they pull in, without ever running the model's code.
Why models need itEvery install decision, by machine and pipeline, in one place your security team can review.
The dashboard“I really liked the product, and that you’re ahead of the market: commit and PR-level review that catches zero-days before a CVE. We invited the team to present to our incident response and offensive security groups.”
Every install decision is logged: the package, the machine, the verdict and the reason. That record supports the system-monitoring (CC7.1) and change-management (CC8.1) controls your auditor tests.
Straight answers from how the product works today.
If the proxy can’t reach CyberXYZ, it reuses any verdict it already reached for that exact package version in the last 24 hours. Otherwise your organization’s setting decides. By default the install is refused with a “retry in a minute” message. Admins can choose to let unchecked installs through instead.
Each install is logged under your organization with the package, version, verdict and reasons, plus the machine, IP address and package manager. Package files are never uploaded to the CyberXYZ API. Downloads do pass through our hosted proxy on their way from the public registry. If someone asks for a package name the public registry doesn’t have, we keep that name, with the machine that asked, for 90 days after the last request, because missing names are how slopsquatting starts. If someone later registers that name and it becomes an open slopsquatting finding, we keep the record as evidence for up to a year.
Yes. Org admins can block packages for the whole organization or for single machines, with an optional expiry, and choose the enforcement level and what happens during an outage. Every change goes into your organization’s audit log.
macOS, Linux and Windows. Your MDM can enroll a whole fleet with one setup command and your organization’s enrollment token. Pipelines run on GitHub Actions, GitLab CI, Azure DevOps and any other CI that runs a shell.
Run xyz proxy remove, or sudo xyz proxy remove on managed machines. It puts each package manager back on its default registry and removes the background agent.
No. You sign up with your work email and your organization’s name. Each sign-up gets its own private workspace, with you as its admin.
Book 15 minutes. We run real packages through CyberXYZ while you watch, including axios 1.14.1, a hijacked release that dropped remote-control malware in March 2026, and show you exactly what your team would see. Then we connect one laptop or one pipeline for a 30-day proof of value.
Check any package, free, and see the verdict we would give it.
Check your inbox. We'll reach out within 24 hours.