Your biggest AppSec blind spot is the code you never wrote.
Attackers don't target your code. They target what you install: packages, MCP servers, IDE and agent extensions. SafeDep blocks malicious packages at every entry point, before they run.
No credit card Free forever for individual use
Start with GitHub
This isn't theoretical.
We find it in real time.
SafeDep analyzes every package published to the major registries, around the clock. Our research team publishes the breakdown, often before the ecosystem has an advisory.
- packages scanned
- 20M+ packages scanned
- components analyzed
- 500K+ components analyzed
- projects secured
- 5000+ projects secured
- avg detection lead
- 14hr avg detection lead
Malicious code doesn't break in.
It gets installed.
Third-party code arrives at every hand-off in your pipeline, from a developer's terminal to an org-wide registry. Each arrival is an execution, and none of it was reviewed by anyone on your team.
Developer machine
AI coding agent
Repository / PR
CI/CD pipeline
Registry / org-wide
SafeDep guards the same five stages.
One policy, enforced everywhere the component travels, so it is inspected before it runs, merges, builds or spreads across the org.
Pick a layer.
See what SafeDep does there.
Credential theft, reverse shells, data exfiltration. These are purpose-built attacks, not bugs a vulnerability scanner can match against a database. Every screen below is the real product.
Block the install, on every machine
SafeDep sits in front of npm, pnpm, pip, uv, bun and other package managers and blocks malicious packages at install time, before any post-install script runs. Every decision lands in one fleet view, alongside a live feed of what was just blocked and where.
- Refused at install time, not flagged next week
- Laptops, CI runners and servers in one view
- Live feed of blocked packages, per endpoint
Every package your agent pulled, with a verdict
SafeDep MCP checks each package an agent wants before it installs. The advisory trail shows which agent asked for what, so a malicious pull is attributed rather than anonymous.
- A verdict per package, attributed to the agent
- Works with Claude Code, Cursor and Windsurf
- Malicious packages refused, not merely flagged
See the AI tooling nobody registered
vet inventories what each machine actually has loaded: coding agents, MCP servers and CLI tools, with scope and version. None of it appears in a lockfile, so none of it shows up in a repo scan.
- Coding agents, MCP servers and CLI tools discovered
- Scoped per machine, per project and per user
- An inventory snapshot, not your source code
Every dependency reviewed before it merges
The GitHub App posts a summary on each pull request: malware, vulnerability and license checks, with a verdict per package. It runs as a required check, so nothing reaches main unreviewed.
- Malware, vulnerability and licence in one report
- A verdict per package, posted on the pull request
- A required check, so nothing merges unreviewed
The build fails before the install lands
SafeDep runs as a proxy in the pipeline and intercepts every package install. A malicious package is stopped before it reaches the runner, and the job exits non-zero on the policy violation.
- Installs intercepted, not audited after the fact
- Blocked before it ever touches the runner
- Fails the job on any policy violation
Start on your laptop.
Roll out to the org.
Every enforcement point is open source and auditable, so there is nothing to take on trust. SafeDep Cloud is what turns those same tools into protection for a whole organization.
For the individual developer
The command-line tools that do the actual blocking. Free forever, and yours to read.
$brew install safedep/tap/pmg - Block malicious installs on your own machine
- Scan any repo or pipeline with policy-as-code
- Guardrails for your AI coding agent
- Apache-2.0, no account, no telemetry
For the security team
Everything in the open source tools, plus the org-wide layer: which components exist, who pulled them in, what policy blocked what, and proof for the audit.
- One policy enforced at every entry point
- Org-wide inventory and component lineage
- Exceptions, approvals and audit history
- SSO, tenants and role-based access control
Threat research from the supply chain frontline
Joyfill npm Packages Compromised with Blockchain C2 Loader
Malicious beta versions of @joyfill/components and @joyfill/layouts published on July 28, 2026 carried the PolinRider blockchain dead drop loader inside their production bundles. The Tron-to-BSC C2 chain, campaign markers, and XOR key rotation match the infrastructure documented in the earlier astro.config.mjs investigation.
mrmustard PyPI Package Trojanized to Steal Credentials
Version 0.7.4 of Xanadu's mrmustard quantum computing library shipped to PyPI with no matching GitHub release. It carries a 258-line credential stealer that harvests SSH keys, AWS and Kubernetes credentials on import and installs three separate persistence hooks, published through a compromised maintainer account after CI tokens were stolen.
@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown
The npm security team removed the original @apexfdn/apex package for malicious code, and the operator re-published the same postinstall macOS infostealer as @copilot-mcp/apex about 11 hours later. It targets Web3 founders and developers, stealing browser data, 20+ crypto wallets, and SSH/AWS/Kubernetes credentials via osascript and curl|zsh, and phones home to a live command-and-control server every 60 seconds. npm has since removed the re-published package too, but the GitHub binaries and C2 infrastructure remain live.
Ship code.
Not malware.
Start free with open source tools on your machine. Scale to a unified platform for your organization.