AI-POWERED THREAT INTEL

The early warning system for zero-days targeting your packages.

Connect your GitHub organization and every engineer gets real-time alerts for the exact packages and versions your repos actually ship, from npm to Go modules: supply-chain attacks, active exploits, and emerging threats. Often before a CVE is published.

Be first when 0Day for Organizations launches. No spam.

You’re on the list. We’ll email you at
Works with your GitHub org Rated 5.0 on the App Store
Alerts Live
Affected
5
Critical
2
lodash@4.17.20 Critical

Prototype-pollution in _.merge, affecting 2 repos.

acme/billing-apiaffected
acme/web-dashboardaffected
LIVE FEED
AI-corroborated across 20+ threat intelligence sources
Socket Google Project Zero Mandiant Wiz Snyk CISA NVD StepSecurity GitHub Advisory
01 / SIGNAL

Signal. Not noise.

Instead of you selecting tools, 0Day reads your organization’s dependency graph (all repos, every transitive dependency) and only alerts on threats that hit a package and version you actually use. Your scanner audits on its own schedule. 0Day tells you the moment something you ship comes under active attack.

Your repos Matched threat
acme/billing-api lodash@4.17.20
acme/edge-proxy gin@1.9.1
acme/mobile-gateway no matches
02 / PIPELINE

How does 0Day catch a threat before the CVE?

AI triages and corroborates every signal across 20+ sources, and each one climbs a three-stage confidence pipeline before it reaches your team.

Candidate

Seen once. A single source flags a package as potentially compromised.

Early Warning

A trusted or corroborated source confirms the signal, and we push it the moment it crosses that bar, often hours or days before it lands in an official advisory or gets a CVE.

WHY IT MATTERSThat head start is the whole point: time to pin a version, open a PR, or pause a deploy before an exploit reaches your repos, not after the patch notes catch up.

Confirmed

Multiple authoritative sources agree. The threat is verified and prioritized.

In practice, it works like this: 0Day continuously ingests raw signals from more than twenty threat intelligence sources: security-research firms, package-registry monitors, government feeds, and advisory databases. When a single source flags a package as potentially compromised, the signal enters the pipeline as a Candidate. When a trusted source or a second independent source corroborates it, the signal is promoted to Early Warning and pushed immediately to every organization whose repositories ship an affected version, typically hours or days before an official advisory is published or a CVE identifier is assigned. When multiple authoritative sources agree, the alert is marked Confirmed. That early-warning head start is the time a team needs to pin a version, open a fix PR, or pause a deploy before an exploit lands.

03 / ON THE RECORD

Two attacks. Two different ways in.

Real incidents, not hypotheticals. Each spread differently, so each diagram below is shaped like the attack it shows.

NPM · SEPT 2025

The “Shai-Hulud” worm

A self-propagating worm compromised maintainer npm tokens and republished trojanized versions of widely-used packages, stealing credentials from each infected machine and using them to infect the next maintainer’s packages in turn.

500+ packages compromised across the dependency graph
HOW 0DAY MITIGATESFlagged at Early Warning, before the trojanized versions reached the registry mirrors your CI pulls from.

Full writeup: what happened and who was affected →

Blast-radius diagram of the Shai-Hulud npm worm: a single compromised maintainer token at the center infects a first tier of widely-used packages such as chalk and debug, which spread the worm to a second tier of dependent packages. A dashed ring marks 0Day's Early Warning boundary: the point where the spread was flagged, before it reached the outer tier of packages that would otherwise have been infected. chalk debug CAUGHT HERE
UPSTREAM BUILD DEP · CVE-2024-3094

The xz-utils backdoor

A years-long social-engineering campaign earned commit access to xz/liblzma and slipped in a backdoor that would have compromised SSH on infected systems. It was caught only when an engineer noticed an unexplained performance regression before it reached stable distro releases.

HOW 0DAY MITIGATES0Day doesn’t wait on a CVE to alert. It surfaces the anomaly the moment any of its 20+ sources flags the release, the same as any other confirmed-threat dependency your org ships.
~3 yrs Trust built by the attacker
Candidate
Early Warning
Confirmed
Minutes For 0Day to alert your team

See the full Incident Watch: every confirmed npm supply chain attack →

Every ecosystem your repos actually depend on.
npm
PyPI
go.mod
RubyGems
crates.io
Maven
NuGet
Composer
04 / NOTIFICATIONS

Push notifications that actually matter to your team.

Connect your GitHub org

A read-only, SBOM-based install at the organization level. We read dependency graphs, never your source code.

GitHub · live GitLab, Bitbucket · coming soon

Push, not doom-scrolling

Stop scrolling security blogs, watching X, and skimming RSS feeds for threats that don’t touch your code. The moment one hits a repo your engineer owns, an iOS push lands. Nothing else to check.

Admin dashboard

Org-wide coverage, members, repositories, and alerts, all in one place, for the people who run security.

05 / PRIVACY

Privacy-first, by default.

No analytics, no tracking SDKs
We don’t profile your engineers or sell data. There’s nothing to opt out of.
Read-only Contents access
The GitHub App reads dependency manifests only, never the contents of your source files.
Revoke anytime
Uninstall the app from GitHub and all access ends immediately. You stay in control.
06 / INSIDE THE APP

Built for how engineers actually work.

Pick your stack once. See only the threats that matter. Act on what’s confirmed. Everything else gets filtered out before it reaches you. Tap a step or a side phone to bring it to the front.

0Day iOS app: pick your stack screen
0Day iOS app: live threat intel stream
iOS push
0Day iOS app: alert detail with affected components and fix
0Day iOS app: notification settings
07 / FAQ

Common questions.

Does 0Day replace our dependency scanner?

No. It sits in front of it. Scanners audit your dependencies and open patch PRs on their own cadence. 0Day is the awareness layer: it pushes an alert the moment a package and version you actually ship is flagged as under attack, often hours or days before an official advisory or CVE exists. Full comparison →

We don’t have a security team. Is 0Day for us?

Yes. 0Day was built for engineering teams without dedicated security staff. Connect your GitHub organization once and every engineer gets push alerts for the repos they own: no triage queue, no dashboard babysitting, no security hire required.

What access does the GitHub App need?

Read-only access to dependency manifests and the dependency graph, never the contents of your source files. Uninstall the app from GitHub and all access ends immediately. Security & Access details →

How is this different from advisory feeds and newsletters?

Feeds report everything; 0Day matches every threat against your organization’s dependency graph (all repos, every transitive dependency) and only alerts when a package and version you actually use is affected. Signal, not noise.

08 / WHO’S BEHIND 0DAY

Built by an engineer, for engineers.

0Day is built and operated by Richard Lous, an independent software engineer based in the Netherlands. It started with a frustration: for months he watched major vulnerabilities surface across half a dozen channels (RSS feeds, X, LinkedIn, vendor blogs, advisory databases, scattered messages from peers). By the time a critical CVE in something he depended on hit his radar, hours (sometimes a full workday) had already passed. Every one of those channels was reactive: you have to be there, scrolling, when it lands. So he built the tool he wanted instead: alerts pushed to your phone, fast, corroborated across 20+ sources, and filtered by what you actually use. The iOS app is live on the App Store, rated 5.0; the organization product extends the same engine to your GitHub org’s full dependency graph, and the waitlist is open.

LinkedIn 0Day on the App Store

Get 0Day for your team.

Join the waitlist and be first when 0Day for Organizations launches.

You’re on the list. We’ll email you at