New threat. Already matched.

Cordon reads every new release as it is published, signs what it confirms into a feed every scanner pulls, and checks everything you already run. No rescan, no waiting for the next build.

  1. 01PublishedA release lands on npm, PyPI, crates, RubyGems, NuGet, Go or Maven.
  2. 02ReadThe watcher reads it as it lands; what static reading cannot settle is detonated in a sandbox.
  3. 03SignedA confirmed verdict enters the feed as a signed, serial-numbered delta.
  4. 04MatchedEvery organisation's stored inventory is checked at once. No rescan.
  5. 05RefusedFirewalls refuse the install, owners hear in chat, pagers and trackers.
  • npm
  • PyPI
  • Cargo
  • RubyGems
  • NuGet
  • Go
  • Maven
The registry watcher

Read as it is published, signed within seconds.

A malicious release is most dangerous in its first hours, before any advisory exists. The watcher reads every release the moment it lands, detonates what reading cannot settle, and publishes what it confirms, so the second install anywhere is refused.

14:01:52 npm event-strem@1.0.3 published by a 4-hour-old account
read install script decodes and runs MALWARE.DROPPER.001
diff against event-stream: one letter away, new install hook
sandbox connect 45.9.148.x:443 (no network, refused)
14:02:04 feed serial 48207 signed published 12 s after release
matched in 3 inventories payments-api, payments-worker, cache
firewall refuses it on npm, everywhere from now
14:02:30 pypi requests-toolbelt-pro 0.1 published
read combosquat of requests-toolbelt, env sent at import MALWARE.EXFIL.001
14:02:41 feed serial 48208 signed published
14:03:05 crates fast-serde 2.1.4 published
read build.rs fetches and runs a script MALWARE.INSTALL.FETCH_EXEC.001
14:03:12 feed serial 48209 signed published
What Cordon knows

More than a list of bad names.

The intel answers the questions an attacker counts on nobody asking: would this range install the bad release, is the package itself recorded, did anything change since the version you trusted.

Known-malicious releases249,646 malicious-package records, matched by name, version and file hash. Each one is planted in a lockfile and checked every release: all of them are caught.
Ranges that would install oneWithout a lockfile, "easy-day-js": "^1.11.21" installs the malicious 1.11.22. Cordon reports the range.
The package you are vettingA published package's own manifest checked against the malicious records.
Names an AI made upDocumented hallucinated package names, and declared dependencies the registry has never had.
What changed since you trusted itA new install hook, new network or process capability, new obfuscation, new binaries or a new publisher, against the release before, on every major registry, and for every package a pull request changes.
Exploited, with a deadlineA KEV or EUVD match in something you ship opens the CRA 24-hour clock.
Sources

Every feed worth having, merged once.

Records arriving from more than one source are kept once, and a record its publisher withdrew is gone from the next delta.

Cordon's registry watcherEvery new release across seven registries, read and, where needed, detonated.
OSVMalicious-package and vulnerability records for every ecosystem it covers.
GitHub advisoriesWith the CVE named beside each GHSA identifier.
Go vulnerability databaseIncluding the vulnerable functions, for call-level reachability.
Ruby Advisory DatabaseRuby advisories OSV does not carry; one advisory in both is kept once.
CISA KEV and ENISA EUVDActively exploited vulnerabilities, raised to CRITICAL whatever their score.
EPSSThe probability a vulnerability is exploited in the next thirty days, as a ranking factor.
Withdrawn records removedA retracted advisory never blocks a build; about 1,400 were dropped in one refresh.
The signed feed

Fresh by default, and it says nothing about you.

Asking a service about your dependencies tells it what you run. The feed works the other way round: everyone pulls the same signed files, and every match happens on your side.

The same files for everyoneStatic and signed, so fetching the feed reveals nothing about what you scan.
Verified like software updatesRoot, timestamp, snapshot and targets checked; rollback and freeze refused.
Stale intel is said out loudPast its age limit, the scan is marked incomplete rather than presented as current.
Air-gapped, the same wayCarried in as a signed bundle and verified before a byte is unpacked.
Matched in minutes

New intel, checked against everything you already run.

Every complete scan leaves an inventory behind. When a package is flagged, Cordon finds it in your repositories, images and repository-manager caches within minutes, with no rescan, and names who owns each.

DefaultThe signed live feed, minutes old. Nothing about your code or dependencies leaves.
cordon-scanner scan .
Air-gappedNo network attempt at all, against a signed bundle. The intel age is reported.
cordon-scanner scan . --offline
DeepRegistry questions too: yanked releases, provenance, the Go checksum database, Maven version ranges, the release before.
cordon-scanner scan . --online

See what you already run.