Stop malicious packages at the registry level, before they reach a single user. Built for registry operators and teams that run their own package infrastructure.
Client Testimonials
Yeeth Security helped us enhance the security framework of the Open VSX Registry. Their work introduced pre-publish checks, quarantine workflows, and threat-informed detection mechanisms that significantly strengthen the platform's security while keeping the publishing process straightforward for extension publishers.
Products
Tools that stop malicious packages before they reach a single developer.
Registries are a high-value target. A single malicious package can reach thousands of developers before anyone notices. Argus plugs into your publish pipeline and runs every submission through a multi-stage analysis before it goes live.
A backdoor published under an account impersonating a well-known open source developer. The extension collected host telemetry and executed arbitrary code received from a remote C2 server. Caught pre-publish. Zero users affected.
Read the ReportSurfaces Argus risk scores directly in your editor. See threat verdicts on installed packages without leaving your IDE — no extra tooling, no context switching.
Supply chain security hooks for Claude Code. Intercepts npm, pip, yarn, pnpm, and cargo install commands before they execute, and checks each package for age, typosquat, and install-script risk signals.
Latest Briefings
Research and analysis from the Yeeth Security team.
Threat Intel
Checking npm package versions is one of the most common things a developer extension does. Six of them showed up from one publisher in un...
Read Briefing
Threat Intel
Two project-flow extensions sit quietly for five minutes after you open your editor. Then they reach out to a free DuckDNS subdomain over...
Read BriefingA single-file VS Code extension on the Microsoft Marketplace impersonates Copilot, DeepSeek, PyPI and KeyBank. On activation it phones gi...
Read Briefing
Threat Intel
Everyone wants a Kanban board inside their editor. Fifteen fake ones hit the Marketplace over ten weeks, each one a different publisher a...
Read Briefing
Threat Intel
A Kanban board for Roblox developers sounds harmless enough. Six of them hit the VS Code Marketplace in three days — same version, same s...
Read Briefing
Threat Intel
Yeeth Security found 28 counterfeit extensions on Open VSX that exfiltrate the editor, hostname and extension identity to a remote server...
Read BriefingGet Started
Schedule a consultation with our security experts to discuss how we can help protect your organization.
Email Us