Passive Dependency Monitor & Compromise Guard
Supply chain security that runs silently. Get alerted when a malicious package hits your lock files — even if you installed it months ago.
When a malicious package is discovered, registries remove it and publish advisories. But there is no system that reaches the developers who already installed it locally.
Malicious code injected into a popular package. Your project installs it via npm install.
Security community discovers the compromise. Registry removes the package version.
Retroactive matching finds the compromised version in your historical lock file snapshots. Instant alert.
One command. 30 seconds. No runtime dependencies.
curl -sSL pdmcguard.com/install.sh | shThe daemon registers as a system service and watches your lock files silently in the background. Zero configuration needed.
Desktop notification, email digest, and web dashboard. Know instantly when something is wrong.
Blocks npm install when a critical advisory matches a dependency in your lock file.
Knows your branch, commit, and remote. Every alert carries full project context.
When a new advisory drops, checks ALL historical lock file snapshots — not just current.
Ties alerts to specific machines. Know exactly which laptop has the compromised package.
Even projects you haven't touched in months are monitored for new threats.
Local advisory cache works without internet. Cloud sync queues and flushes when you reconnect.
Daemon auto-discovers projects by watching file system events. Install and forget.
npm, PyPI, Go, Rust, Ruby, PHP — one daemon covers your entire stack.
Active Monitoring Cluster // Node-04
03
LIVE
12
MONITORED
04
STABLE
18
30D AVG
colors@1.4.0
api-gateway
event-stream@3.3.6
frontend-app
lodash@4.17.15
analytics-svc
Active Projects
| Name | Ecosystem | Status |
|---|---|---|
| api-gateway | Node.js | error |
| frontend-app | Node.js | error |
| data-pipeline | Python | check_circle |
| auth-service | Go | check_circle |
Infrastructure
| Machine | Projects | Alerts | |
|---|---|---|---|
| dev-macbook-pro | 8 active | 02 | |
| dev-workstation | 3 active | 01 | |
| homelab-server | 1 active | 00 |
Join the waitlist now and get full access when we launch.
Join the waitlist and get early access when we launch.