
Lottie Player (2024)
Attackers injected cryptocurrency miners during npm package builds, exploiting dynamic linking weaknesses that static analyzers missed. Over 4 million deployments were affected before detection.
Plug and play protection for modern DevOps pipelines.
Integrate with your pipeline in minutes.
Surface only high priority issues.
Actionable alerts wherever your team works.
“There are a lot of tools that process security advisory data, but Garnet is the first I've seen that goes a step further, applying behavioral analysis to find issues before they get reported to an advisory database. This is the kind of thing we'd always wanted to do at npm, Inc., but never got around to. It's super exciting to see it come to fruition. ”
Isaac Z. Schlueter, NPM, Inc
“I don’t know about you, but having zero observability and no security enforcement in a CI/CD pipeline like GitHub Actions feels pretty scary... I’m looking forward to testing Jibril by Garnet”
Teodor Podobnik, Greenish
“Dynamic analysis of libraries at build-time is a game changer. It will annihilate a whole new class of vulnerabilities if it works. ”
Ryotax Xin, DogeWallet
Real-time runtime monitoring for network, file and process behaviours in your host environment.
Stop malicious activity like cryptomining, exfiltration, and tampering with out-of-the-box detections and threat intelligence. Stay ahead of supply chain threats—wherever they emerge.
Detect and respond to incidents inside your existing workflow and tools–without the context switch.
Gain visibility into unknown threats.
Provide your email and we'll keep you up to date with everything Garnet.