QuickFox, operated by Xiamen Kezhensai Technology Co., Ltd., has announced a partnership with Murphy Security (墨菲安全), a well-known Chinese cybersecurity vendor specializing in software supply chain security. The two companies will collaborate systematically on software composition identification, vulnerability risk detection, supply chain poisoning detection, license compliance management, and continuous supply chain risk monitoring, working around the specific product characteristics of QuickFox’s multi-platform client software to further improve the security and trustworthiness of its client products.
About QuickFox
QuickFox is a return-to-China VPN service released by Xiamen Kezhensai Technology Co., Ltd., built for overseas Chinese communities and Chinese students studying abroad. It covers use cases including domestic video streaming, gaming, and live streaming, and provides clients for Windows, macOS, Android, iOS, and TV, helping overseas users access China-based content platforms smoothly.
From a product engineering standpoint, QuickFox carries the typical profile of overseas-facing internet software: multiple client platforms iterating in parallel, continuous version releases, delivery pipelines spanning different platform ecosystems and third-party component dependencies, and a software composition that has to be managed continuously across projects and versions. As a client product that carries network transmission capabilities, its stability and security bear directly on user experience and data safety, which makes every link in the software supply chain worth treating rigorously.
Why the Partnership: Supply Chain Risk Is Harder to Govern in Overseas-Facing Clients
For any internet product, what a user sees is a client, a service, a feature. Behind it, hundreds or even thousands of open-source components and third-party dependencies may already be running. An open-source component helps an engineering team implement features quickly, and it can equally become a potential entry point into the software supply chain through vulnerabilities, malicious code, or version-related risk.
For overseas-facing internet companies, this kind of risk is usually distributed outside the business code itself; open-source dependencies, third-party SDKs, build tools, installation packages, and update pipelines can each become an entry point. Parallel multi-platform development, rapid version iteration, heavy third-party SDK usage, and complex distribution channels make it significantly harder to judge how far a risk reaches. Once a risky component enters a client, the impact extends to users’ local devices, overseas network environments, app stores, download sites, partner channels, and legacy versions still in circulation, raising the cost of investigation, replacement, takedown, user outreach, and impact explanation.
More importantly, what companies face is no longer the static question of whether a vulnerability exists, but whether they can continuously manage the software composition inside their products. Open-source components keep being introduced, client versions keep iterating, and new vulnerability and poisoning intelligence keeps emerging. A single scan at any point in time is not enough to support security operations. This is the core problem the two companies aim to solve together.
Scope of Collaboration: Four Directions
Building a Software Composition Inventory Across Client Platforms
The two parties will jointly and continuously identify open-source components, component versions, transitive dependencies, and third-party SDKs across QuickFox’s different clients, progressively building the relationships between projects, components, and versions, so that risk assessment can be located down to the specific platforms, projects, and versions involved.
Extending Detection of Supply Chain Poisoning and Anomalous Components
Beyond publicly disclosed vulnerabilities, the two parties will jointly monitor malicious components, counterfeit packages, anomalous versions, and other supply chain poisoning risks. When new information about a malicious package or anomalous component appears in the open-source ecosystem, software composition data can be used to determine faster whether existing clients are involved, reducing the pressure of manual investigation.
Moving Risk Checks into the Development and Release Process
Working with QuickFox’s development and delivery workflow, the two parties will shift risk checks earlier into dependency introduction, build, and release, establishing unified identification and handling rules for high-risk vulnerabilities, malicious dependencies, anomalous versions, and license risks, reducing the chance that high-risk components enter official release artifacts.
Accumulating Traceable Risk-Handling Records
Around risk discovery, impact scoping, remediation tracking, retest confirmation, and record retention, the two parties will progressively form a closed loop of continuous governance, letting development, security, and release teams collaborate on the same set of data and reach impact localization and remediation decisions faster when new vulnerabilities or poisoning risks appear.
Value: Continuous Governance Across the Product Lifecycle
The significance of the partnership is upgrading open-source governance from a one-time scan to a continuous capability. Software composition identification, vulnerability and poisoning detection, and risk analysis and remediation will be progressively integrated into QuickFox’s client development, build, release, and operations stages, so that security is no longer an after-the-fact patch but an underlying capability that accompanies product evolution.
For QuickFox users, this means more transparent software composition, more timely risk remediation, and more standardized compliance management, with product security and trustworthiness continuously reinforced, so that while QuickFox is used to accelerate video streaming, gaming, and live streaming, a continuously operating supply chain security mechanism is running behind it.
Looking Ahead
The partnership is an important step in QuickFox’s effort to improve its product security system. Going forward, QuickFox will further deepen collaboration with Murphy Security and more security organizations, continuously improving risk discovery, early warning, and response capabilities, providing users with safer, more stable, and more trustworthy products and services, and jointly advancing the construction and improvement of the software supply chain security ecosystem for overseas-facing internet client products.