About Extuno

The update is the attack surface.

A package can be clean for a year and hostile on its next release. Extuno diffs every version against the one before it, then reports what changed and the evidence for it. We do that across twelve ecosystems, using static, dynamic, and AI analysis.

Why we exist

The problem, in one diff

v3.1.0
v3.1.1
v3.1.2
One update turns a trusted package into an exfiltration tool.
1002+
Detection rules
11
Ecosystems covered
5
Tests on every version
91%
Findings carry evidence
How we work

Everything you submit runs the same pipeline.

Every submission runs the same seven steps. Static analysis and a live run come first, an AI layer reviews both, and a diff against the last version isolates what this release changed. Score and report follow, evidence attached to each finding.

Discover
01
Acquire
02
Static
03
Dynamic
04
Diff
05
Score
06
Report
07
What we value

A finding without a file path is not a finding.

Principle

Traceable to an artifact

Every statement names the file, the line, the payload that matched, and the version it appeared in.

Principle

Functional color

Teal is clean, amber is review, coral is critical. If the color changed, the severity changed.

Principle

Actionable findings

Every finding ships a recommended action. A score on its own does not tell you what to fix.

Who is behind Extuno

Tolga SEZER researches the attacks and writes the detection rules.

Extuno was founded by Tolga SEZER, a founder and security researcher who studies how browser extensions and developer packages are compromised through their update channel. He writes the Extuno blog and turns that research into the platform's detection. Connect on LinkedIn.