Capabilities

Every finding names the file, the line, and the request that triggered it.

Every extension and package runs the full battery: vulnerability and secret-leak testing, static and dynamic analysis, AI code analysis. Findings come back in one evidence format, naming the file, the change, why it is dangerous, and what to do next.

Supply chain - example inspectionexample
event-stream 3.3.6
npm package
3.3.5->3.3.6
Static
Dynamic
AI
Analyzing update
Version-diff detection

Attackers ship the payload in an update, not the version you installed.

Every update is compared against the version before it. A release that scored clean and now scores critical is band escalation, and the diff names the change that caused it.

  • + New exfiltration channels introduced on update
  • + Added permissions and weakened content policy
  • + New remote-code paths that evade review
Supply-chain diff

Update lineage

v3.0.9
v3.1.0
v3.1.1
v3.1.2
Sandbox run #48212 critical
  1. 1.4.0reviewed on release
  2. 1.4.1no change to permissions or hosts
  3. 1.4.2new outbound host in background.js:214
  4. 1.4.3not published yet
cookie exfilwallet readmic request
Dynamic sandbox

The package executes in a throwaway VM, and every host it contacts is recorded.

Extuno executes the real extension or package in an ephemeral, network-segmented micro-VM and records exactly what it does.

  • + Network endpoints and outbound payloads
  • + Credential, session, and wallet theft
  • + Crypto-miners and covert command traffic
Static analysis

1100+ rules read the code. One score, and every point traces to the rule that added it.

Capability abuse, remote code, credential theft, evasion, surveillance, covert command traffic, obfuscation. That is what the rules look for, on every version.

  • + Severity-banded: clean, review, critical
  • + A rule that fires returns a file path, a line number, and the matched snippet
  • + Exportable as SARIF, or a non-zero exit from the CI gate
Capability abuseclean
Remote code (MV3)critical
Credential theftcritical
Evasionreview
Obfuscationreview
Vulnerability testing

A clean extension can still ship an exploitable bug.

An exploitable release does not have to be a malicious one. Extuno tests each version for vulnerable code paths and dependencies with known CVEs, and reports them whether or not anyone put them there on purpose.

  • + Unsafe API and injection-prone patterns
  • + Vulnerable and outdated dependencies
  • + Every finding mapped to its location and fix
Vulnerability report3 issues
Prototype pollutioncritical
unsafe merge in util.js
Outdated dependencyreview
axios 0.21.1 - known CVEs
Unsafe innerHTMLreview
DOM sink without sanitize
AI analysis

It reads every version in full, then compares what the other layers found.

An analysis layer reads the complete source of every version and correlates it with the static and dynamic results. It clusters related findings and matches code against known-malware behavior. Behavior that does not appear in the package's earlier versions is flagged as an anomaly.

  • +

    AI review is advisory. It reads the source and explains a finding, but it never changes a verdict or a gate result - the rule engine and the sandbox decide.

    Reads the full source code of every version
  • + Anomaly flags against prior versions
  • + Known-malware similarity and campaign clustering
  • + Every flag links back to its evidence
Correlationanomaly
Static + dynamic agreecritical
both layers flag exfiltration
Behavior unlike prior versionscritical
new outbound host on this release
Similar to known campaignreview
matches a clustered family
Pull request gate
gate failed - 1 secret
Secret-leak testing

A pass/fail check on every pull request.

1000+ anchored secret detectors test extensions and packages for leaked keys, tokens, and credentials. Point them at your own repos too. Findings come back as SARIF, with git-history scanning and baseline support.

  • + Standard SARIF output for code scanning
  • + Git-history and baseline support
  • + GitHub and GitLab pipelines
Continuous monitoring

A monitor re-scans when the published version actually changes, not on a timer.

Add extensions and packages to a watchlist and route findings to the channels your team already uses.

Monitoring

Watchlist

Track any extension or package across all twelve ecosystems.

Monitoring

Alert lifecycle

Alerts move from open to acknowledged to resolved. The audit trail records every change.

Monitoring

Delivery

SIEM, Slack, Teams, PagerDuty, email, and signed webhooks.