Introducing Package Firewall
Endor Labs has launched Package Firewall, a new capability that blocks malicious, vulnerable, and non-compliant open-source packages before they reach developer machines or CI runners. The firewall sits between developer tools (including AI coding agents like Cursor and Claude Code), private registries, and public repositories, intercepting every install request. It uses a real-time malware feed updated within minutes of new package releases, with an AI-enhanced analysis pipeline that scans npm, PyPI, and Go ecosystems. The tool addresses the sharp rise in software supply chain attacks—including a 14x increase in OSV malware advisories over two years and 92% of npm account takeovers occurring in 2025. Recent incidents like backdoored versions of popular packages (lightning, axios, telnyx) highlight the need for immediate enforcement. Beyond malware, Package Firewall enforces organizational policies to block packages with known vulnerabilities or license violations and supports features like cooldown periods to avoid high-risk new releases. It can be deployed integrated with private registries like JFrog Artifactory or directly on endpoints via MDM, with all events logged for visibility.
https://www.endorlabs.com/learn/introducing-package-firewall
Comments
Post a Comment