Dazio landing preview
Dazio by Boost Security
How it works Compare FAQ Docs INSTALL DAZIO

Find out in two minutes if your developer machine is already infected.

Dazio is free (forever!). It finds malware and exposed secrets already on your machine, then stops new malware at every install. It runs so light you'll forget it's there, and your data never leaves your device.

dazio scan

Fake packages should never get to run.
With Dazio, they don't.

npm install, with Dazio running
Block malware at install

Dazio checks every package before it runs and blocks the bad ones, with a note on what it caught. It also finds malware that landed before you installed it.

Find your exposed secrets

API keys in markdown files your agent wrote, tokens in shell history, forgotten .env files. Dazio finds them before malware does.

Harden your toolchain

Package managers ship with safety settings off. Dazio finds each one and shows you exactly what to change. (We're adding IDE and agent checks soon.)

Your agent installed something last night.

If it was malware, you'd probably never know (until you were already pwned).
Attackers found a way in that your existing protection can't touch:
→
You prompt.

Your agent runs npm install and pulls in forty packages you never read.

→
A fake package slips in.

An attacker published it six hours ago, one letter off the name you meant.

→
Your keys leave.

Its install script grabs your .env, shell history, and AWS credentials, and sends them to whoever wrote it.

You keep coding.

The build passes and you move on. Days later, someone logs in as you.

It keeps happening to careful people:

Check your machine once, or at every install.

ONE-TIME SCAN

Scans your home folder for malware, exposed secrets, and settings worth fixing. Two minutes to a report. Run it the day an attack hits the news.

ALWAYS-ON DAEMON

One command sets it up. From then on it checks every package before it installs and blocks malware on the spot, without an approval queue or a new workflow. Covers the install your agent runs at 2am.

Ready? Let's install Dazio.

(It takes about a minute.)
Homebrew, on macOS or Linux:
brew install boostsecurityio/tap/dazio
Without Homebrew, on macOS or Linux:
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/boostsecurityio/dazio/HEAD/install.sh)"

That installs the latest release into ~/.local/bin, checking its checksum against the release's checksums.txt. Run it again to upgrade.

Or with mise:
mise use -g github:boostsecurityio/dazio

A mise upgrade replaces the binary without telling the daemon, so run dazio service restart after one if you have continuous protection on.

Package managers covered:

npm logo
npm
JAVASCRIPT
PyPI logo
PyPI
PYTHON
RubyGems logo
RubyGems
RUBY
Cargo logo
Cargo
RUST
Go logo
Go
GO MODULES
NuGet logo
NuGet
.NET
Maven logo
Maven
COMING NEXT
With Dazio, you can:
Keep up with your agent
Dazio watches pip inside virtualenvs, uv, uvx, plus whatever your agent runs.
Get threat feed updates hourly
We built an enterprise-grade feed into Dazio and update it hourly. You don't set anything up.

Yes, actually free (forever).

Our friends and family all build with AI now. We built Dazio so the next attack skips them (and you). We believe in the power of free tools, so we're keeping this one free.

Looking for enterprise capabilities?
Boost has you covered. Developer Endpoint Protection adds central management, reporting, and support on top of everything Dazio does.
LEARN ABOUT DEVELOPER ENDPOINT PROTECTION →

FAQ

Which package managers does Dazio support?

npm, pip (including inside virtualenvs), uv and uvx, RubyGems, Cargo, NuGet, and Go modules today. Maven support is in progress.

I already have antivirus, and my company runs an EDR. Why do I need this?

Keep them; they do a different job. Antivirus and EDR inspect binaries and catch code that's already running. A malicious package is a plain-text script that arrives through a tool you trust, and it runs with your permissions the moment it installs. By the time an EDR notices anything, your tokens have already left. Dazio blocks the package before the install finishes.

Does it run on my machine?

Dazio runs on macOS and Linux.

Will it slow down my installs?

You won't feel it. Dazio checks each package right on your machine, against its local copy of the feed, so the lookup finishes before the download does.

What leaves my machine?

Almost nothing. Dazio keeps the threat feed on your laptop and checks packages there, so even package names stay put. We collect counts (packages per ecosystem, number of findings) and get an alert when Dazio blocks real malware: which malware, which package, nothing else. Your code, your secrets, and your scan results stay with you.

Dazio by Boost Security
BOOSTSECURITY.IO Boost Security