Dazio is free (forever!). It finds malware and exposed secrets already on your machine, then stops new malware at every install. It runs so light you'll forget it's there, and your data never leaves your device.
Dazio checks every package before it runs and blocks the bad ones, with a note on what it caught. It also finds malware that landed before you installed it.
API keys in markdown files your agent wrote, tokens in shell history, forgotten .env files. Dazio finds them before malware does.
Package managers ship with safety settings off. Dazio finds each one and shows you exactly what to change. (We're adding IDE and agent checks soon.)
Your agent runs npm install and pulls in forty packages you never read.
An attacker published it six hours ago, one letter off the name you meant.
Its install script grabs your .env, shell history, and AWS credentials, and sends them to whoever wrote it.
The build passes and you move on. Days later, someone logs in as you.
Scans your home folder for malware, exposed secrets, and settings worth fixing. Two minutes to a report. Run it the day an attack hits the news.
One command sets it up. From then on it checks every package before it installs and blocks malware on the spot, without an approval queue or a new workflow. Covers the install your agent runs at 2am.
That installs the latest release into ~/.local/bin, checking its checksum against the release's checksums.txt. Run it again to upgrade.
A mise upgrade replaces the binary without telling the daemon, so run dazio service restart after one if you have continuous protection on.
Our friends and family all build with AI now. We built Dazio so the next attack skips them (and you). We believe in the power of free tools, so we're keeping this one free.
npm, pip (including inside virtualenvs), uv and uvx, RubyGems, Cargo, NuGet, and Go modules today. Maven support is in progress.
Keep them; they do a different job. Antivirus and EDR inspect binaries and catch code that's already running. A malicious package is a plain-text script that arrives through a tool you trust, and it runs with your permissions the moment it installs. By the time an EDR notices anything, your tokens have already left. Dazio blocks the package before the install finishes.
Dazio runs on macOS and Linux.
You won't feel it. Dazio checks each package right on your machine, against its local copy of the feed, so the lookup finishes before the download does.
Almost nothing. Dazio keeps the threat feed on your laptop and checks packages there, so even package names stay put. We collect counts (packages per ecosystem, number of findings) and get an alert when Dazio blocks real malware: which malware, which package, nothing else. Your code, your secrets, and your scan results stay with you.