Neutralize Supply Risks At the Source.

Stop malicious packages at the registry level, before they reach a single user. Built for registry operators and teams that run their own package infrastructure.

Scanning Ecosystems
OPEN VSX
VS CODE
NPM SOON
PYPI SOON
Defends IDEs
VS Code Cursor Windsurf VSCodium Gitpod Antigravity Codespaces Void Theia
Argus Registry Malware Interception
Tactical Log Feed
FILTER: CRITICAL_ONLY
[--:--:--] Initializing defensive protocols...

Client Testimonials

See why teams trust us

Yeeth Security helped us enhance the security framework of the Open VSX Registry. Their work introduced pre-publish checks, quarantine workflows, and threat-informed detection mechanisms that significantly strengthen the platform's security while keeping the publishing process straightforward for extension publishers.
Christopher Guindon
Christopher Guindon Director, Software Development — Eclipse Foundation

Products

Purpose-built supply chain defense

Tools that stop malicious packages before they reach a single developer.

Scans Run
Threats Blocked
Campaigns Tracked
Registry Security

Argus

Registries are a high-value target. A single malicious package can reach thousands of developers before anyone notices. Argus plugs into your publish pipeline and runs every submission through a multi-stage analysis before it goes live.

YARA
AST
Network
Fuzzy Hash
AI Synthesis
Risk Score
  • Blocks malicious packages before any user can download them
  • Works with public registries and self-hosted package infrastructure
  • We work with registries to build and deploy scanning infrastructure end-to-end
  • Webhook alerts to Discord, Slack and HMAC endpoints
Request Access
Scan Feed SCANNING...
Featured Detection

SleepyDuck

A backdoor published under an account impersonating a well-known open source developer. The extension collected host telemetry and executed arbitrary code received from a remote C2 server. Caught pre-publish. Zero users affected.

Read the Report
Extension Nomic.hardhat
Campaign SleepyDuck
Vector Publisher Impersonation
C2 function.undefined21[.]com
Verdict THREAT  · 96
Developer Tooling

DevGuard

Surfaces Argus risk scores directly in your editor. See threat verdicts on installed packages without leaving your IDE — no extra tooling, no context switching.

  • Inline risk scores on every installed extension
  • Real-time flags for packages Argus marks as threats
  • Free to install from Open VSX
Compatible IDEs
VS Code Cursor Windsurf VSCodium Gitpod Antigravity Codespaces Void Theia
Downloads
Version
AGPL-3.0 License
Install DevGuard
Open VSX · Extensions
Prettier esbenp.prettier-vscode
CLEAN
ESLint dbaeumer.vscode-eslint
CLEAN
Solidity nomic.hardhat
THREAT · 96
GitLens eamodio.gitlens
CLEAN
Claude Code Integration

Yeeth Claw

Supply chain security hooks for Claude Code. Intercepts npm, pip, yarn, pnpm, and cargo install commands before they execute, and checks each package for age, typosquat, and install-script risk signals.

  • Blocks suspicious installs before Claude Code runs them
  • Flags brand-new packages, typosquats, and postinstall scripts
  • Optional Argus API integration for full static analysis
Get Yeeth Claw
Install
$ openclaw skills install yeeth-claw
Hook installed to ~/.claude/hooks/openclaw/
Claude Code · PreToolUse Hook
$ npm install chalk
Yeeth Claw: package published 3 days ago
BLOCKED: age < 7d + install script detected
Submitted to Argus for analysis
$ _

Latest Briefings

Threat intelligence from the field

Research and analysis from the Yeeth Security team.

Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm Dropper Malware Analysis
Jul 2, 2026

Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm Dropper

The VS Code extension ascii-fetcher.ascii-fetcher looked harmless because almost all of its code lived in a dependency. That dependency, ...

Read Briefing
The Windows Installer Dropper Family: VS Code Extensions Living off the Land Threat Intel
Jul 2, 2026

The Windows Installer Dropper Family: VS Code Extensions Living off the Land

In late June Argus caught a cluster of VS Code: droppers that all abused Windows installer primitives — curl|bash, irm|iex, cscript, msht...

Read Briefing
The Fake MSDN DLL Dropper and the Counterfeit C++ Runtime Malware Analysis
Jul 2, 2026

The Fake MSDN DLL Dropper and the Counterfeit C++ Runtime

The worldline.aicodefix campaign downloads a counterfeit VCRUNTIME140.dll from a fake Microsoft domain, plants it inside a spoofed Edge u...

Read Briefing
DigitalBarberTrim's Side-Car Loader: A VSIX Installer That Pivots Across VS Code Forks Malware Analysis
Jul 2, 2026

DigitalBarberTrim's Side-Car Loader: A VSIX Installer That Pivots Across VS Code Forks

The DigitalBarberTrim.html-entity-codec campaign version-cycled through clean, malicious, and stub releases. The payload was a hidden i.j...

Read Briefing
The Solidity Extension That Stole from the Clipboard: Inside the ethdevtools Crypto Swap Threat Intel
Jun 21, 2026

The Solidity Extension That Stole from the Clipboard: Inside the ethdevtools Crypto Swap

A fake Solidity language extension hid in VS Code: for weeks before activating. Once it did, it scraped the clipboard for crypto seeds an...

Read Briefing
The Scanner Is the Target: How IDE Extension Malware Uses Prompt Injection to Evade AI Review Threat Research
Jun 18, 2026

The Scanner Is the Target: How IDE Extension Malware Uses Prompt Injection to Evade AI Review

Malicious VS Code and Open VSX extensions are now embedding fake system instructions and context floods aimed directly at the AI-powered ...

Read Briefing
As seen in The Hacker News Mentioned for our discovery of the ByteBinTools backdoor in the VS Code Marketplace.

Get Started

Ready to secure your development environment?

Schedule a consultation with our security experts to discuss how we can help protect your organization.

Book a Call