Vetting anything with an install button
Koi Security was founded in 2024 by three alumni of Israel's Unit 8200, Amit Assaraf, Idan Dardikman and Itay Kruk, to build a checkpoint for software people install themselves: browser extensions, packages, containers, MCP servers and AI agents. Its Supply Chain Gateway product used an AI risk engine, called Wings, to classify and sandbox that software before it reached an endpoint. [2]
The founders' origin story doubled as a proof of concept. They found a gap in the VS Code Marketplace's review process, built a fake theme extension called Darcula Official that quietly exfiltrated source code, and had it infect more than 300 organizations, including a major endpoint security vendor and a national court network, within a week. [2]
From seed to a $400 million exit
Koi raised a seed round in late 2024 from Picture Capital, NFX and Cerca Partners, followed by a $38 million Series A in September 2025 led by Battery Ventures and Team8, bringing its total funding to roughly $48 million. [2]
Palo Alto Networks agreed to acquire Koi for a reported $400 million in February 2026 and completed the deal that April, folding the product into its Prisma AIRS and Cortex XDR lines under a new "agentic endpoint security" category. Koi's own site now redirects entirely to Palo Alto Networks; the roughly 60-person team had been protecting more than 500,000 endpoints at the time of the deal. [3][4]
The report that put it on the map
On December 15, 2025, Koi published research on eight Chrome and Edge extensions from a single publisher, including Urban VPN Proxy and 1ClickVPN Proxy, with more than 8 million combined installs. Its Wings engine had flagged that the extensions were intercepting raw traffic to ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok and Meta AI and forwarding it to an affiliated data broker, changes Koi traced to a silent update the previous July. [5]
Google and Microsoft removed the extensions from their respective stores following the disclosure. [6]
A widening research footprint, and a lawsuit
The Urban VPN report was one entry in a steady stream of supply-chain disclosures Koi published through 2025 and 2026, covering malicious npm packages, compromised VS Code and browser extensions, and what it described as the first malicious MCP server found in the wild, an npm package that used the protocol AI coding agents rely on to reach external tools as cover for stealing credentials. [8]
That research record also produced a lawsuit. In 2026, the U.S. company MeetingTV sued Koi and Palo Alto Networks, alleging that Koi's December 2025 DarkSpectre report wrongly identified MeetingTV's domain as espionage infrastructure linked to a Chinese threat actor, an error MeetingTV attributed to a mistake by Koi's Wings system, and that the resulting classification got the domain automatically blocked by security vendors worldwide. Koi later updated the report to say a review had found no evidence linking MeetingTV to the threat actor in question. The case was still pending as of the date these sources were checked, and both defendants have disputed the claims. [7]
Sources
- Endpoint Security Platform for Extensions, Packages & MCPs | Koi
Koi Security · Aug 20, 2026
- Cyber startup Koi raises $38M Series A after uncovering VS Code Marketplace flaw
Calcalist / CTech · Sep 10, 2025
- Palo Alto Networks acquires one-year-old Israeli startup Koi for $400 million
Calcalist / CTech · Feb 17, 2026
- Palo Alto Networks Completes Acquisition of Koi to Secure the Agentic Endpoint
Palo Alto Networks · Apr 14, 2026
- 8 Million Users' AI Conversations Sold for Profit by 'Privacy' Extensions
Koi Security · Dec 15, 2025
- Featured Chrome Browser Extension Caught Intercepting Millions of Users' AI Chats
The Hacker News · Dec 15, 2025
- Palo Alto Networks and Koi Security sued over alleged AI error in cyber threat report
Calcalist / CTech · Jul 5, 2026
- First Malicious MCP Server Found on npm Stealing Emails via Postmark Backdoor
The Hacker News · Sep 29, 2025