Zyrax — software supply-chain security
New — coming soon

Stop malicious code
before it enters your supply chain.

Zyrax is building a platform to keep malicious and risky code out of the software you ship. The first piece is already here, and it is free.

zyrax-guard
SYS.01
status
pre-launch
free tool
zyrax-guard
ecosystems
npm · PyPI · crates
github action
tiagosilva07/zyrax-guard@v0
engine
static · zero-dep
license
MIT (free CLI)
View source on GitHub
zyrax-guard — ~/project — zsh
zyrax-guard check lodahs
BLOCK lodahs@0.0.1-security
name is similar to "lodash" — did you mean: lodash
MAL-2025-25502: Malicious code in lodahs (npm)
zyrax-guard check lodash
SAFE lodash@4.18.1 — no signals
Verified acrossnpm/PyPI/crates.io
01 / Available now
Free · open-source · MIT

Six checks. Zero config. Nothing leaves your machine.

Zyrax Guard vets every npm, PyPI, and crates dependency before you install it, running in milliseconds against public registry metadata.

06.1

Typosquatting

Flags names one keystroke from popular packages, like reqeusts instead of requests.

06.2

Known malware

Cross-checks public security advisories for confirmed-bad packages.

06.3

Hallucinated names

Catches packages that do not exist on the registry, including AI-suggested names that were never published.

06.4

New & unused

Warns on brand-new, low-adoption packages nothing is depending on yet.

06.5

Lockfile integrity

Detects tampered or mismatched lockfile entries in your pull requests.

06.6

Maintainer change

Surfaces sudden ownership handoffs, a classic account-takeover signal.

./--deep

Opt in and Zyrax Guard downloads the package and statically inspects the code it runs at install time, things like network calls, process spawning, and obfuscated eval, then blocks the dangerous combinations. No sandbox, no Docker, zero dependencies.

$ go install github.com/tiagosilva07/zyrax-guard/cmd/zyrax-guard@latestor grab a binary from Releases
View releases on GitHub →
— / Use it everywhereGitHub Marketplace ↗
T.1

Terminal

zyrax-guard check lodash

Any shell · macOS · Linux · Windows

T.2

CI · GitHub Actions

uses: tiagosilva07/zyrax-guard@v0

Gate every pull request · SARIF output

T.3

AI agents · MCP

claude mcp add zyrax-guard …

Claude · Cursor · Windsurf · VS Code

02 / In development
The Zyrax platform

From one machine to your whole organization.

The free tool protects one developer. The platform protects everything you ship, across every team and repository.

P.1

Continuous monitoring

Every dependency across all your repositories, watched in real time.

P.2

Organization policy

Set your security rules once and enforce them across every team and repo.

P.3

Dashboard & audit

Full visibility, audit trails, and compliance-ready reports for security teams.

P.4

Threat intelligence

A curated feed that flags malicious packages before they reach public databases.

> early-access enrollment

Be first through the door.

Join the waitlist for early access and launch updates. We will only email you about Zyrax, and you can unsubscribe at any time.

Data protection / GDPR · RGPD

Weget Unipessoal Lda. collects the email address, and optional name, you submit, solely to notify you about Zyrax early access and its launch, on the basis of your consent. We do not sell or share your data. You can remove your data instantly at any time. See our Privacy Policy for full details.