joint security program

Recently, QuickFox (Xiamen Kezhensai Technology Co., Ltd.) and Murphy Security (墨菲安全), a famous Chinese cybersecurity vendor working in software supply chain security, came together to design client-side software supply chain security governance. They will partner in software composition identification, vulnerability risk detection, supply chain poisoning detection, license compliance management, and continuous supply chain risk monitoring. This will manage the product form of QuickFox’s multi-platform clients and will try to improve the security and trustworthiness of those products.

Read the full blog to learn more about the joint program in supply chain management.

The service and its footprint

QuickFox is a return-to-China VPN service developed by Xiamen Kezhensai Technology Co., Ltd. for overseas Chinese communities and Chinese students studying abroad. It includes domestic video streaming, gaming, and live streaming, and provides clients on Windows, macOS, Android, iOS, and TV so that overseas users can access China-based content platforms smoothly. Service details are published at quick-fox.com.

The product has the characteristics typical of overseas-facing internet software. Multiple clients iterate in parallel. Versions are released continuously. Delivery pipelines span different platform ecosystems and third-party component dependencies. The resulting software composition requires continuous management across projects and versions rather than a one-off audit. Because QuickFox is a client product carrying network transmission capabilities, its stability and security relate directly to user experience and data safety, making every link in the supply chain worth serious treatment.

The risk picture behind the program

What a user looks at in any internet product is a client, a service, a feature. Behind it, hundreds or even thousands of open-source components and third-party dependencies may already be operating. An open-source component can help a development team implement functionality immediately, and it can also become a potential entry point into the software supply chain through vulnerabilities, malicious code, or version risk.

For overseas-facing internet companies

The risk is often distributed outside the business code: open-source dependencies, third-party SDKs, build tools, installation packages, and update pipelines can all serve as entry points. The specific traits of overseas-facing products — parallel multi-platform operation, quick version iteration, a larger number of third-party SDKs, and complex distribution channels — make it markedly difficult to judge how far a risk’s impact reaches.

Once a risky component enters a client, the impact spreads to users’ local devices, overseas network environments, app stores, download sites, partner channels, and the installed base of legacy versions. Investigation, replacement, takedown, user outreach, and impact explanation all become more costly.

And the question companies face has changed shape. It is no longer the static one of whether a vulnerability exists, but whether the software composition inside a product can be handled continuously — because open-source components keep being introduced, client versions keep iterating, and new vulnerability and poisoning intelligence keeps appearing. A single scan at a common point in time is not sufficient to support security operations. That is the core issue this partnership sets out to address.

What the program covers

Based on the features of QuickFox’s multi-platform clients, the collaboration runs along four directions.

Establishing a software composition inventory across the clients

The two parties will continuously identify open-source components, component versions, transitive dependencies, and third-party SDKs in QuickFox’s different clients, progressively creating the association between projects, components, and versions, so that risk assessment can be located to the specific clients, projects, and versions involved.

Extending detection of supply chain poisoning and anomalous components

Beyond publicly disclosed vulnerabilities, the two parties will combinatorially track malicious components, counterfeit packages, anomalous versions, and other poisoning risks. 

When new malicious package or anomalous component information appears in the open-source ecosystem, composition data offers a faster determination of whether existing clients are involved, easing the load of manual investigation.

Moving risk checks into the development and release process

Combined with QuickFox’s development and delivery workflow, risk checks will move earlier into dependency introduction, build, and release, with unified identification and handling rules for high-risk vulnerabilities, malicious dependencies, anomalous versions, and license risks, reducing the chance of high-risk components entering official release artifacts.

Accumulating traceable risk-handling records

Covering risk discovery, impact scoping, remediation tracking, retest confirmation, and record retention, the two parties will progressively form a closed loop of continuous governance, with development, security, and release teams working from the same data so that impact localization and remediation decisions arrive quicker on the next vulnerability or poisoning event.

Intended outcome

The main significance of the program is upgrading open-source governance from a one-time scan to a continuous capability. Software composition identification, vulnerability and poisoning detection, and risk analysis and remediation will be progressively integrated into QuickFox’s client development, build, release, and operations, so that security is an underlying capability accompanying product evolution instead of an after-the-fact repair.

For users of the service, the described result is more transparent software composition, more timely risk remediation, and more standardized compliance management, with security and trustworthiness continuously reinforced — so that while the service is used to accelerate video streaming, gaming, and live streaming, a continuously running supply chain security mechanism is at work behind it.

QuickFox has framed the partnership as a crucial step in improving its product security system, and has indicated it will continue deepening collaboration with Murphy Security and further security organizations on risk discovery, early warning, and response, providing users with safer, more stable, and more trustworthy products and services. They are jointly advancing the construction and improvement of the software supply chain security ecosystem for overseas-facing internet client products.

FAQs

QuickFox and Murphy Security launched a joint project to check vulnerabilities and provide protection to clients in the software supply chain.

The goal of the QuickFox and Murphy partnership is to strengthen software composition analysis and govern clients’ software supply chain risks

When a risky component enters a client system, the impact spreads to users’ local devices, overseas network environments, app stores, download sites, partner channels, and the installed base of legacy versions.
Related Posts
×