Safety’s cover photo
Safety

Safety

Computer and Network Security

Vancouver, British Columbia 2,759 followers

About us

Every company is racing to adopt AI, but AI-driven development has created a massive blind spot. Developer workstations are overflowing with tools, extensions, and packages that security teams can't see. Safety gives you real-time visibility into what's actually installed across your developers' machines, so you can embrace AI without flying blind. We go where traditional security doesn't: local development machines and employee workstations, not just CI/CD. We see what others miss. IDE extensions, AI models, MCP servers, and the full software supply chain. And we do it silently: secure by default, no developer opt-in required. Our cybersecurity research team maintains the industry's most comprehensive vulnerability database, detecting 4x more vulnerabilities than public sources like NVD and GitHub Security. We were among the first to identify attacks like Shai Hulud and fake Claude Code. Trusted by Wiz, Nokia, AWS, Adyen, and FannieMae, supporting millions of monthly scans. Products: Safety Platform · Safety Firewall · Safety CLI · Vulnerability Database · Safety MCP You can't govern what you can't see. We make it visible. getsafety.com

Website
https://getsafety.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Vancouver, British Columbia
Type
Privately Held
Specialties
Software Supply Chain Security, Dependency Management, Cybersecurity, Python, DevSecOps, Vulnerability Management, DevOps, Cybersecurity Research, Malicious Package Detection, Data Science, Artificial Intelligence, Machine Learning, Vulnerability Scanning, Vulnerability Detection, Vulnerability Prioritization, Typosquatting, Javascript, Software Development, Saas, and Enterprise Software

Employees at Safety

View 23 employees at Safety

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

Updates

  • Safety reposted this

    🤖 If you’re a CISO and you’re not experimenting with AI and AI development tools, you’re falling behind. But not because of what you might think… You just simply won’t be able to keep pace with what’s required to SECURE these development workflows. 3 things CISOs should be doing/thinking about in order to secure AI development in your organizations: 1) Know your stack If you don’t know what AI tools are being used on your developer workstations, you’ve already lost. Of course it’s impossible to know *everything*. But you should have a pretty good idea of the totality of tools being used in your environment. Don’t rely on your team for this. You have to know. Both for strategic reasons. Like should you be using Claude or Codex and why. But also for security reasons. Like when zero days and vulnerabilities and supply chain attacks affect those products. Because there’s no shortage of those… Knowing what you have is foundational to IT/Security and it’s foundational to the CISOs role. 2) Know the technology CISOs need to be the most prepared and informed person in the room. How else can you make good decisions if you’re not? The best way to learn and understand new technology is to use it yourself. It’s not enough to know you have Claude and Codex in the environment. You have to know what those tools can do! Play around with Claude or Codex. Try to “vibe” code something. Spend some time playing around with these AI development tools. Firstly, it’s super fun. Secondly, you will begin to understand how they work at a high level and what their capable of. Pay attention to what the model is doing after you give it a prompt. Is it searching the internet? Reading your local files? Modifying local files? Running commands on your behalf? Communicating via APIs on your behalf? 3) Talk to developers Anyone whose been in this position knows how empowering and awesome it is. That is, when your boss or leadership team come to you and ask you “how can I help you be more successful?” It sounds silly but that really does make a difference. Now just change it slightly. “How can I help you be more successful and where are there potential security gaps we should address?” You’re no longer mandating security controls. You’re no longer demanding they do their work in a certain way. You’re honestly trying to meet them where their at and help them do their work, efficiently and securely. That’s where Safety comes in. What I like about Safety is that they are focused on securing modern developer workstations without requiring changes to tools and workflows developers already use. Safety gives security teams visibility and governance over the modern developer workstation: packages, AI coding tools, MCP servers, IDE extensions, containers, and local developer tooling. If you are responsible for securing developer workstations in the age of AI-assisted development, check out Safety. (link in comments) Thank you to Safety for sponsoring this post.

  • View organization page for Safety

    2,759 followers

    36 fake Strapi plugins. 31 unique payloads. One postinstall hook. Between March 31 and April 4, we tracked a campaign that published 36 malicious npm packages disguised as Strapi CMS community plugins. These weren't typical credential stealers. From a single npm install, attackers could escape containers, spray credentials across SSH and Postgres, dump databases, mine git history for secrets, and establish persistent C2 implants. The payloads were hostname-gated — they only executed on machines matching prod-strapi. Most sandboxes would miss them entirely. Full technical breakdown with IOCs, campaign timeline, and remediation steps on our blog. See the link in the comments. #SupplyChainSecurity #npm #DevSecOps

  • View organization page for Safety

    2,759 followers

    The maintainer of one of the most popular JavaScript packages, Axios, has been compromised. This led to what could become one of the largest software supply chain attacks ever. Axios is downloaded over 100 million times a week and is used in literally millions of applications. It doesn't get much bigger than this. The Safety research team analysed the attack and identified that versions 1.14.1 and 0.30.4 are malicious. You can read our blog post about it here 👉 https://lnkd.in/gam2kwTc

    • No alternative text description for this image
  • View organization page for Safety

    2,759 followers

    🚨 The TeamPCP campaign just hit the Telnyx Python SDK 🚨 The telnyx package on PyPI was compromised — versions 4.87.1 and 4.87.2 contain credential-stealing malware. This package gets ~790K monthly downloads and is deployed across production communications infrastructure. Version 4.87.0 is confirmed clean. Pin to that version immediately. This is the same campaign that hit LiteLLM three days ago. TeamPCP is burning through stolen publishing tokens and compromising whatever they can reach — four waves, nine days, five ecosystems, over 1,000 organizations affected so far. If your environment ran either compromised version, treat it as a full credential-exposure event and rotate everything. Full breakdown and remediation steps on our blog 👉 Link in comments

  • View organization page for Safety

    2,759 followers

    507 malicious packages across npm and PyPI in February. Down from 652 in January, but the interesting shift is where they're coming from. PyPI's share has tripled since December — from 11% to 33%. Python's dominance in AI/ML pipelines is making it a bigger target, and the data is starting to reflect that. Our research team also uncovered a WhatsApp botnet campaign (DGXeon) hiding in npm packages that impersonate the Baileys library. It doesn't steal credentials or crypto, it hijacks your authenticated WhatsApp session to inflate follower counts on the attacker's channels. Some of the packages are still live on npm. The full breakdown, including a dependency confusion wave targeting HashiCorp, IKEA, Proton, and Qualys, is in our February supply chain threats report. Link in comments.

    • No alternative text description for this image
  • View organization page for Safety

    2,759 followers

    Developer workstations are the new perimeter. And most security teams have zero visibility into them. At #RSAC2026 this week, Check Point's Head of Vulnerability Research presented something that should concern every security leader: AI coding assistants, Claude Code, Cursor, Codex CLI, Gemini CLI — contain architectural vulnerabilities that turn developer machines into open attack surfaces. No suspicious executables. No phishing links. No traditional indicators of compromise. Backdoors executing with full privileges through tools developers trust and use every day. This isn't theoretical. Data shows 63% of organizations can't enforce limits on AI agents operating inside their infrastructure — accessing files, making decisions, taking actions. At Safety, we built for exactly this moment. Independent, workstation-level visibility across your entire developer fleet, every AI tool, package, extension, and MCP server, without relying on those tools to police themselves. What you can't see, you can't govern. What you can't govern will eventually hurt you. Come find me at RSAC. Let's talk about what's actually running on your developers' machines. #RSAC2026 #DevSecOps #AISecurity #WorkstationSecurity

  • Safety reposted this

    Andrej Karpathy just explained the scariest thing happening in software right now — the liteLLM PyPI supply chain attack: "Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any dependency you could be pulling in a poisoned package anywhere deep inside its entire dependency tree. This is especially risky with large projects that might have lots and lots of dependencies" (rest of the tweet in the comments) A quick breakdown: liteLLM gets 97 million downloads a month, and with the malicious version, a simple pip install was enough to steal everything on your machine: SSH keys, AWS credentials, crypto wallets, database passwords, git credentials, SSL private keys. Incredibly, the only reason this attack was discovered was a bug in the exploit that hogged RAM — which someone eventually noticed. Karpathy's take is the wake-up call: every time you install any package, you're trusting every single dependency in its tree, and any one of them could be poisoned. Even worse, every time your AI agent builds for you it's importing packages and other tools, each of which has its own dependency tree. Software supply chain security is now listed as the number one concern for organizations worldwide, according to a recent OWASP community survey — and it's only getting worse. Anyone developing software needs to be aware of this, and for those using AI agents like Claude Code, Codex, or Cursor, it's essential. Safety's Endpoint security is the best defence against these attacks for development endpoints: * Supply chain governance — applying your policies directly at the AI agent and package manager level. Attacks are blocked before they reach your systems. * Accurate inventory and risk reporting across packages, IDE extensions, MCPs and Skills, powered by our industry-leading proprietary data. * Proactive attack prevention through our package firewalls and MCP tools. It's comprehensive risk reporting combined with a security layer protecting against malicious packages and other real-time attacks. DM me to get onto our 30-day pilot.

  • View organization page for Safety

    2,759 followers

    Claude can now use your computer. Not suggest or autocomplete a line. Actually point, click, open apps, browse the web, and navigate your screen autonomously. Anthropic just shipped Computer Use — and it's the kind of shift we've been building Safety Workstation for. Think about what this means - an AI agent that doesn't just operate inside a terminal or IDE, but moves across your entire desktop. Opening files, launching applications, installing software/packages, connecting to services - all on the developer's local machine. This is incredible for productivity, and it's a massive expansion of the attack surface that security teams need to think about. EDR sees a legitimate process. Your MDM sees a managed device. Neither sees what the agent is actually doing, which apps it opened, which files it accessed, packages downloaded, or which services it connected to. This is why we built Safety for the workstation layer. The companies that figure out how to enable this securely will move fastest, and we're helping them do this. Read more at https://getsafety.com #AIsecurity #supplychainsecurity #workstationsecurity

    • No alternative text description for this image
  • Safety reposted this

    Three malicious packages are live on NPM right now. We've been tracking the DGXeon campaign at Safety: a WhatsApp botnet targeting developers building bots with Baileys. The attack is layered: npm aliasing tricks, runtime file patching, and hardcoded pairing codes that give attackers persistent access to victims' WhatsApp accounts. Removing the package doesn't remove the attacker's linked device. We discovered and reported these. As of today, they're still available: → @dgxeon13/libsignal-node → dgxeon-baileys → dgxeon-soket-buttonx If you're building WhatsApp bots, check your dependencies. Full breakdown in our February supply chain report 👇 https://lnkd.in/ebJ78QPq

Similar pages

Browse jobs