Stop malicious packages at the registry level, before they reach a single user. Built for registry operators and teams that run their own package infrastructure.
Client Testimonials
Yeeth Security helped us enhance the security framework of the Open VSX Registry. Their work introduced pre-publish checks, quarantine workflows, and threat-informed detection mechanisms that significantly strengthen the platform's security while keeping the publishing process straightforward for extension publishers.
Products
Tools that stop malicious packages before they reach a single developer.
Registries are a high-value target. A single malicious package can reach thousands of developers before anyone notices. Argus plugs into your publish pipeline and runs every submission through a multi-stage analysis before it goes live.
A backdoor published under an account impersonating a well-known open source developer. The extension collected host telemetry and executed arbitrary code received from a remote C2 server. Caught pre-publish. Zero users affected.
Read the ReportSurfaces Argus risk scores directly in your editor. See threat verdicts on installed packages without leaving your IDE — no extra tooling, no context switching.
Supply chain security hooks for Claude Code. Intercepts npm, pip, yarn, pnpm, and cargo install commands before they execute, and checks each package for age, typosquat, and install-script risk signals.
Latest Briefings
Research and analysis from the Yeeth Security team.
Malware Analysis
The VS Code extension ascii-fetcher.ascii-fetcher looked harmless because almost all of its code lived in a dependency. That dependency, ...
Read Briefing
Threat Intel
In late June Argus caught a cluster of VS Code: droppers that all abused Windows installer primitives — curl|bash, irm|iex, cscript, msht...
Read Briefing
Malware Analysis
The worldline.aicodefix campaign downloads a counterfeit VCRUNTIME140.dll from a fake Microsoft domain, plants it inside a spoofed Edge u...
Read Briefing
Malware Analysis
The DigitalBarberTrim.html-entity-codec campaign version-cycled through clean, malicious, and stub releases. The payload was a hidden i.j...
Read Briefing
Threat Intel
A fake Solidity language extension hid in VS Code: for weeks before activating. Once it did, it scraped the clipboard for crypto seeds an...
Read Briefing
Threat Research
Malicious VS Code and Open VSX extensions are now embedding fake system instructions and context floods aimed directly at the AI-powered ...
Read BriefingGet Started
Schedule a consultation with our security experts to discuss how we can help protect your organization.
Book a Call