Detection method

How version diffing catches poisoned updates

In short

Version diffing compares each release of an extension or package against the one before it, then reports what the update added: new permissions, new endpoints, new code paths. It is how Extuno catches a benign project that was poisoned through its update channel.

Why diff versions instead of scanning once?

A one-time scan answers is this version bad today. It cannot catch the project that was clean when you adopted it and malicious three updates later. Diffing answers the question that actually matters for supply chain risk: what did this update change, and is any of it dangerous.

What does a version diff surface?

Band escalation across the update, clean to dangerous. Sensitive permissions added, or host access broadened. An outbound or command-and-control endpoint that was not in the last version. A weakened Content-Security-Policy. A new remote-code path. New install-time behavior. Each delta carries the evidence behind it.

How does Extuno score a risky update?

Extuno reads each version statically and dynamically, computes the deltas, and raises an alert when the new version crosses from benign into dangerous. Every point in the score traces back to a rule and a finding, and the headline signal is the band escalation an update introduces.

FAQ

Common questions

What is band escalation?
The risk band of an extension or package rises from one version to the next because the update added malicious or high-risk behavior. Clean last release, dangerous this one. That jump is the core supply-chain alert.
Does diffing produce false positives on normal updates?
Benign updates add features, not exfiltration. Extuno's deltas are defined as new dangerous behavior present in the new version and absent in the old, so routine updates stay quiet.