Something new is coming

The next layer of supply-chain security is on its way.

Zyrax is building a platform to keep malicious and risky code out of the software you ship. The first piece is already here, and it is free.

Get early access Try the free tool →

Available now · Free & open-source

Start with the free CLI

Zyrax Guard checks your npm, PyPI, and crates dependencies for malicious or risky packages before you install them. No signup, no config, and nothing ever leaves your machine.

Typosquatting

Flags names one keystroke away from popular packages, like reqeusts instead of requests.

Known malware

Cross-checks curated and public advisory feeds for confirmed-bad packages.

Hallucinated names

Catches AI-suggested packages that do not actually exist on the registry.

New & unused

Warns on brand-new, low-adoption packages that nobody is depending on yet.

Lockfile integrity

Detects tampered or mismatched lockfile entries in your pull requests.

Maintainer change

Surfaces sudden ownership or maintainer handoffs, a classic takeover signal.

Add --deep and Zyrax Guard downloads the package and statically inspects the code it runs at install time, things like network calls, process spawning, and obfuscated eval, then blocks the dangerous combinations. No sandbox, no Docker, and zero dependencies.

GitHub, opening soon
The platform · Coming soon

From one developer to your whole organization

The free tool protects one machine. The platform will protect everything you ship, across every team and repository.

🛰️

Continuous monitoring

Every dependency across all your repositories, watched in real time.

🏢

Organization policy

Set your security rules once and enforce them across every team and repo.

📊

Dashboard & audit

Full visibility, audit trails, and compliance-ready reports for your security team.

🛡️

Threat intelligence

A curated feed that flags malicious packages before they reach public databases.

Early access opening soon