Every malicious-package record in the bundled intel, across npm, PyPI, NuGet, RubyGems, Cargo, Go, Maven, Composer and VS Code, planted in a lockfile and scanned: 287,899 checks, none missed.
bench/malicious_records.pyKnow what runs before it runs.
Supply-chain and AI-agent security. Every package, pipeline and MCP server checked before anything executes.
Every one of 249,646 known-malicious package records caught. 94.2% of 39,328 real malicious packages detected. 99.6% agreement with Trivy across 190,000 packages in real lockfiles. How it was measured
npm
PyPI
Cargo
Go
Maven
Gradle
NuGet
Composer
RubyGems
CocoaPods
Pub
Swift
Hex
CRAN
Conan
Conda
Bazel
Hackage
Julia
opam
Homebrew
Nix
vcpkg
GitHub Actions
Terraform
Helm
Ansible Galaxy
Container images
Kubernetes
GitLab
Jenkins
CircleCI
MCP
Claude
Cursor
GitHub Copilot
One command. Nothing executed.
Repositories, packages, images, machines, SBOMs, pipelines and infrastructure, read without running a line. Free, and offline if you want it.
Every item, not a sample. More malware, a tenth of the false blocks.
Every number is produced by a script in the open-source repository, over whole corpora of real malware, real lockfiles and real agent attacks nobody on the project wrote. A gate people keep switched on is one that does not cry wolf.
The lockfiles of the most-downloaded projects on 14 registries, compared package by package. 98.7% of lockfiles agree on average, 12 of 14 registries at 98% or above, and every gap was read: each Cordon defect it found is fixed.
bench/parse_agreement.py3,941 of 4,034 attacks, each on its rule's scan path; 80.6% of the published evasions, read offline for intent; 92.4% of the catalogue's benign near-misses left clean.
bench/atr_bench.pyA compromised repository never reaches your disk.
A repository is most dangerous the moment it arrives: an editor runs its tasks, an agent reads its rules, an install runs its hooks. Cordon checks the commit from git's own objects before anything is checked out or merged, so a teammate whose machine was compromised cannot pass it on to you.
- Clone
cordon-scanner clonescanned from git's objects; checked out only if it passes - Pull
cordon-scanner pullthe incoming commit scanned; merged only if it passes - Switch
post-checkout hooka blocked branch or clone undone before it runs - Review
cordon-scanner reviewwhat a dependency update adds, on the pull request - Commit
pre-commit hookthe staged bytes, read from the index - Push
pre-push hookevery tracked file and the history - Install
package firewallknown malware refused before a byte lands
cordon-scanner clone https://github.com/acme/app.git# blocked: nothing checked out, the clone removedcordon-scanner pull# blocked: not merged, your checkout unchangedcordon-scanner guard install --global# every future git clone, checkout and pull, checked
- Anything malicious blocks, from a known-malicious release in a lockfile to a poisoned agent config.
- The code cannot configure its own check: no config, policy or baseline inside it is read.
- Plain git is covered too: a blocked pull is reset, a blocked branch switch goes back, a blocked clone is emptied, all before anything runs.
- How it works, in tutorial 22
A security tool you can install everywhere.
A scanner runs on every laptop and every CI runner, next to your keys and your publish tokens. Cordon is built so that being there is never the risk.
Eighteen minutes from publish to owned.
A typosquat lands on npm. Cordon does not wait for your next scan: new intel is matched against what every repository, image and cache already contains.
- 13:51[email protected] is publishedOne letter from event-stream, by an account created that morning.
- 14:02Intel flags itIts install script fetches a payload and runs it. Read from the tarball; nothing executed.
- 14:03Matched against every inventoryTwo repositories and an Artifactory cache, found without a rescan.
- 14:03Refused at the firewallFour installs today never landed. One CI job that bypassed the firewall is named.
- 14:09Owned and ticketedOwner from CODEOWNERS, PagerDuty paged, PAY-412 opened in Jira, 48-hour SLA running.
Every new release, read as it is published.
Cordon watches npm, PyPI, crates, RubyGems, NuGet, Go and Maven and reads every release the moment it lands. What it confirms reaches every scanner and every firewall through a signed feed, so the next install is refused before your next scan.
One list, owned and on the clock.
Malware, agents in CI on events anyone can raise, unpinned MCP servers, hidden text in rules files: grouped by rule, owned through CODEOWNERS, each with an SLA. Only a complete scan can close one.
Everything that can run in your build or your agent.
- detection rules
- 1,384
- Agent Threat Rules
- 815
- package ecosystems
- 28
Dependencies
28 ecosystems and the lockfiles they write, Bun and Deno included, from npm and PyPI to Conan, Hex, CRAN and Bazel.
- Malware by behaviour in Python, JavaScript, Ruby, PHP, Go, Rust, Java, .NET, Swift, Kotlin and twelve more languages
- Known-malicious releases, and version ranges that would install one
- CVEs with reachability down to the vulnerable function, CISA KEV and EU EUVD marked
- Typosquats, combosquats, lookalike scopes and AI-hallucinated names
- Dependency confusion against your internal namespaces
Builds and pipelines
GitHub Actions, GitLab, Jenkins, Azure, CircleCI, Bitbucket and Buildkite.
- Workflows that run a stranger's code with your secrets (pull_request_target, workflow_run)
- Script injection from issue titles, branch names and commit messages, in every CI dialect
- Secrets sent off the runner, poisoned caches and artefacts
- Compromised and unpinned actions and reusable workflows
- Makefiles, CMake, MSBuild, Gradle and build.rs that fetch and run code
Agents and MCP
Every coding agent in use, 49 of 49 configuration locations, read without starting one.
- 815 Agent Threat Rules, and prompt injection in eleven languages
- Hooks and MCP launches that fetch and run, exfiltrate or open a shell
- MCP servers handed the Docker socket, host root or a plain-http remote
- Poisoned tool descriptions, from local and remote servers alike
- Remote MCP servers read as they serve now, and any tool changed since you approved it
Artefacts
Whatever arrives through the supply chain, opened and read, never run.
- Archives inside archives, safely, with bombs and path escapes refused
- Binaries by what they import, with YARA and ClamAV hand-off
- Model files that execute on load: pickles, PyTorch, Keras
- Models loaded with trust_remote_code, or with a loader's safety switch turned off
- Office macros, remote templates, PDF launch actions
Secrets
60 credential types, anchored to each issuer's real format.
- In the tree, the index and the whole git history
- Checked live with the issuer, only when you ask
- A secret plus egress reported as theft, not a leak
- Reported by hash, never by value
Infrastructure
862 policies generated from the providers' own schemas, plus hand-written rules.
- Terraform, CloudFormation, Kubernetes, Helm, Compose and Ansible
- Images a Kubernetes workload runs: pinned by tag, or with no signature or provenance
- Missing encryption, public exposure, deletion protection, weak TLS
- Found by content, wherever a manifest sits
- Reported as posture, so it informs without breaking builds
Malware never reaches a laptop.
Every install from npm, PyPI, Maven, Go, NuGet, RubyGems and crates is decided in milliseconds, upstream of your repository manager. Known malware and public packages that shadow your internal names are refused before a byte lands.
See every agent, and what it can do.
Rules files, MCP servers and AI agents in CI, read statically across repositories and laptops. Hidden instructions and excess rights surface on day one.
Nothing left unscanned.
What is not being scanned matters more than what is. Every gap is named, with how Cordon knows.
An exploited CVE, a shipped release, a deadline.
Evidence is sealed per release: SBOM, VEX, AI-BOM and signed scans of exactly what shipped. When CISA KEV lists a flaw in something you ship, the ENISA draft and its clock are already open.
Ask your estate anything.
Plain questions in the console, Slack or Teams, answered from your own records with your permissions, and every answer cited.
The scanner finds it. The platform stops it, everywhere.
The open-source scanner is whole and free. Cordon Cloud adds what a team needs to act on it across every repository, laptop and pipeline, and to know about a new attack before the next scan.
Running in an afternoon.
Observe first, block later. Nothing you connect today fails a build: Cordon baselines everything, shows what it would have blocked, and you promote teams to warn and block when the noise is triaged.