
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
zevr-guard
Block ads, trackers, malware & phishing. See who your browser talks to on a live world map. No setup — 100% local, no data sent.
Your browser talks to dozens of companies on every page you visit. Zevr Guard shows you exactly who — on a live world map — and blocks the dangerous ones automatically.
Install once. No setup, no account. Protection starts the moment you add it.
━━━ WHY ZEVR GUARD ━━━
✔ Blocks malware & phishing with a threat list that updates itself daily — no waiting for extension updates ✔ Detects lookalike phishing domains (examp1e.com, exаmple.com, example.com.verify-account.net) with on-device heuristics — caught even before they reach any blocklist ✔ Blocks entire countries with one tap — see a connection you don't like on the map, block everything from that region ✔ Guards password entry: warns before you type a password on an unencrypted page, a suspected lookalike, or a site you've never signed into ✔ Identifies the companies behind 115,000+ tracker signals, not just cryptic domain names ✔ 100% local matching — your browsing URLs never leave your device. No telemetry, ever ✔ Built for Manifest V3 from day one — works today, works after the MV2 shutdown ✔ Fully open source (GPL-3.0) — every claim above is verifiable in the code
━━━ WHAT YOU'LL SEE ━━━
Screenshots use seeded sample data so the popup, side panel, and warning screen can be shown clearly in a single image. The "Dangerous" risk score shown for zevrhq.com (our own site) is a demonstration value — in real use, every score is computed from the actual third-party connections seen on that page. zevrhq.com itself is not classified as malicious; it's used only as a placeholder host.
━━━ HOW IT WORKS ━━━
Zevr Guard never sends your browsing history anywhere. The only automatic outbound request is a daily fetch of threat-list updates from our CDN — it carries no information about you or the sites you visit. The single exception is one you control: clicking "Report as phishing" sends that one domain name to us for review, and nothing else. Don't take our word for it: the code is public.
━━━ OPEN SOURCE ━━━
Source code (GPL-3.0): https://github.com/krystasis/zevr-guard
FAQs
Block ads, trackers, malware & phishing. See who your browser talks to on a live world map. No setup — 100% local, no data sent.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.