Catch supply chain attacks before release.
Bitbison detects compromise at every step from source to release as it happens, enabling you to block compromised builds before they ship.
In production at semiconductor, automotive and fintech companies
Existing security tools cannot detect most supply chain attacks. Bitbison detects them from full systems provenance, a complete record of cause and effect across your systems.
Deployment
and integrations
Deploy the Bitbison agent across source control servers, build runners and artifact servers.
Source servers
Deploy the agent to self-hosted source control servers. Its runtime recording catches compromise of the host and changes to repositories that bypass your normal workflow.
Build runners
Deploy the Bitbison agent to your ephemeral or self-hosted runners to detect and block supply chain attacks. Its runtime recording catches host implants and inputs or changes the build cannot account for.
Artifact servers
Deploy the agent to registries and release servers. Its runtime recording catches compromise of the host and any published artifact that cannot be traced back to a trusted build.
CI and build systems
- GitHub Actions
- GitLab CI
- Jenkins
- Buildkite
- Blacksmith
- Kubernetes
- Docker and BuildKit
- Podman
Languages and build tools
- RustCargo
- C/C++Make, Autotools, CMake
- GoGo modules
- Pythonuv, Poetry, Pipenv, pip
- Java and KotlinMaven, Gradle
- AndroidGradle, Android SDK
- .NETNuGet, MSBuild
- RubyBundler, RubyGems
- JavaScriptnpm
- TypeScriptnpm, tsc, esbuild
- DenoJSR, npm
- Flutter and Dartpub
Comprehensive detection
and prevention
Detect and stop attacks across the software supply chain. Each stage below shows a real attack and what Bitbison detects.
Source code · xz · 2024
A maintainer hid a backdoor in test files.
The build scripts decoded it into an object and linked it into liblzma. Two xz releases shipped with it.
Released 24 Feb 2024 · Found 29 Mar 2024
Original disclosureDetected by Bitbison
Bitbison traces where each part of liblzma came from and flags the one that doesn’t belong.
Source control · PHP · 2021
Attackers pushed a backdoor to PHP’s git server.
Two commits on the self-hosted server used the names of core developers. Maintainers caught them before a release.
Pushed 28 Mar 2021 · Caught before release
PHP.Watch reportDetected by Bitbison
Bitbison continuously records all activity on the source control server.
Dependencies · Shai-Hulud · 2025
A worm ran inside npm installs.
Its install script stole GitHub tokens and cloud keys, then published infected versions of other packages. More than 500 packages were compromised.
First package 14 Sep 2025 · Disclosed 15 Sep 2025
CISA alertDetected by Bitbison
Bitbison flags the install script when it reads credentials and sends them out of the build.
Build · SolarWinds · 2020
Malware on the build server swapped a source file.
SUNSPOT replaced a file while Orion was compiled. Signed updates carried the backdoor to up to 18,000 customers.
Shipped Mar 2020 · Found Dec 2020
CrowdStrike analysisDetected by Bitbison
Bitbison flags the implant reading the compiler’s memory and traces the source file it swapped.
Release · Go mirror · 2021–2025
A mirror served a backdoored module for three years.
Go’s module mirror cached a backdoored lookalike of boltdb. Its GitHub tag was then rewritten to clean code.
Cached Nov 2021 · Found Feb 2025
Socket analysisDetected by Bitbison
Bitbison flags any published artifact it cannot trace back to a trusted build.
Policy
and governance
Centralize security policies across all your builds and track dependency risk across repositories.
Compliance
and audit
Bitbison keeps a complete history of every build, down to each process, file and network connection. Show auditors and customers what shipped, what went into it and how it was built.

Runtime
protection
Bitbison checks behavioral and data flow policies against recorded activity to detect poisoning attacks and other breaches before, during and between builds.
Research
All postsSqueezing Performance out of eBPF
What eBPF hooks, kernel reads, maps, rings, and arenas actually cost, measured across cores.
Langflow RCE: 34 minutes to server compromise
We analyzed how a popular AI infrastructure platform is being exploited in the wild.
Shai-Hulud rebuilt as a standalone stealer
A new standalone Mini Shai-Hulud variant delivered through React2Shell with an SSH worm and Global Socket reverse shell.
“Bitbison is the most significant advancement in runtime security I’ve seen in my career.”
“This is the only solution that can tell me what did not happen on my systems.”
“The capabilities of Bitbison are game changing. I predict that within 18 months you will simply not be able to execute in infosec without a tool with comparable capabilities.”
See Bitbison in action
Walk through a build with one of our founders and discuss how Bitbison would fit your setup.
