Skip to content

Catch supply chain attacks before release.

Bitbison detects compromise at every step from source to release as it happens, enabling you to block compromised builds before they ship.

In production at semiconductor, automotive and fintech companies

Existing security tools cannot detect most supply chain attacks. Bitbison detects them from full systems provenance, a complete record of cause and effect across your systems.

Deployment
and integrations

Deploy the Bitbison agent across source control servers, build runners and artifact servers.

Source servers

Deploy the agent to self-hosted source control servers. Its runtime recording catches compromise of the host and changes to repositories that bypass your normal workflow.

Build runners

Deploy the Bitbison agent to your ephemeral or self-hosted runners to detect and block supply chain attacks. Its runtime recording catches host implants and inputs or changes the build cannot account for.

Artifact servers

Deploy the agent to registries and release servers. Its runtime recording catches compromise of the host and any published artifact that cannot be traced back to a trusted build.

CI and build systems

  • GitHub Actions
  • GitLab CI
  • Jenkins
  • Buildkite
  • Blacksmith
  • Kubernetes
  • Docker and BuildKit
  • Podman

Languages and build tools

  • RustCargo
  • C/C++Make, Autotools, CMake
  • GoGo modules
  • Pythonuv, Poetry, Pipenv, pip
  • Java and KotlinMaven, Gradle
  • AndroidGradle, Android SDK
  • .NETNuGet, MSBuild
  • RubyBundler, RubyGems
  • JavaScriptnpm
  • TypeScriptnpm, tsc, esbuild
  • DenoJSR, npm
  • Flutter and Dartpub

Comprehensive detection
and prevention

Detect and stop attacks across the software supply chain. Each stage below shows a real attack and what Bitbison detects.

Source code · xz · 2024

A maintainer hid a backdoor in test files.

The build scripts decoded it into an object and linked it into liblzma. Two xz releases shipped with it.

Released 24 Feb 2024 · Found 29 Mar 2024

Original disclosure

Detected by Bitbison

Bitbison traces where each part of liblzma came from and flags the one that doesn’t belong.

Source control · PHP · 2021

Attackers pushed a backdoor to PHP’s git server.

Two commits on the self-hosted server used the names of core developers. Maintainers caught them before a release.

Pushed 28 Mar 2021 · Caught before release

PHP.Watch report

Detected by Bitbison

Bitbison continuously records all activity on the source control server.

Dependencies · Shai-Hulud · 2025

A worm ran inside npm installs.

Its install script stole GitHub tokens and cloud keys, then published infected versions of other packages. More than 500 packages were compromised.

First package 14 Sep 2025 · Disclosed 15 Sep 2025

CISA alert

Detected by Bitbison

Bitbison flags the install script when it reads credentials and sends them out of the build.

Build · SolarWinds · 2020

Malware on the build server swapped a source file.

SUNSPOT replaced a file while Orion was compiled. Signed updates carried the backdoor to up to 18,000 customers.

Shipped Mar 2020 · Found Dec 2020

CrowdStrike analysis

Detected by Bitbison

Bitbison flags the implant reading the compiler’s memory and traces the source file it swapped.

Release · Go mirror · 2021–2025

A mirror served a backdoored module for three years.

Go’s module mirror cached a backdoored lookalike of boltdb. Its GitHub tag was then rewritten to clean code.

Cached Nov 2021 · Found Feb 2025

Socket analysis

Detected by Bitbison

Bitbison flags any published artifact it cannot trace back to a trusted build.

Policy
and governance

Centralize security policies across all your builds and track dependency risk across repositories.

Compliance
and audit

Bitbison keeps a complete history of every build, down to each process, file and network connection. Show auditors and customers what shipped, what went into it and how it was built.

A Bitbison event log from a host: every process, file operation and network connection with its time, action, user, process and target

Runtime
protection

Bitbison checks behavioral and data flow policies against recorded activity to detect poisoning attacks and other breaches before, during and between builds.

“Bitbison is the most significant advancement in runtime security I’ve seen in my career.”

Christopher KeyFormer Chief Product Officer of Mandiant and founder of Verodin

“This is the only solution that can tell me what did not happen on my systems.”

Head of Security EngineeringLarge semiconductor company

“The capabilities of Bitbison are game changing. I predict that within 18 months you will simply not be able to execute in infosec without a tool with comparable capabilities.”

Theo SchlossnagleFounder of SparkPost and author of Scalable Internet Architectures

See Bitbison in action

Walk through a build with one of our founders and discuss how Bitbison would fit your setup.

We’ll only contact you about your Bitbison demo.