Introducing Malware Detection and Response Automation

Semgrep Supply Chain now includes Malware Detection and Response Automation, providing end-to-end protection during package compromises.

September 24th, 2026

Tl;dr:

Semgrep Supply Chain now covers the whole path for malicious dependencies: detecting exposure within minutes, responding automatically, and blocking malware before it's installed.

Detection
  • Expert-verified, automated rule generation adds advisories for a new supply chain incident within minutes.

  • Automated full rescans check customers’ codebases using incident-specific rules, quickly surfacing affected repos and projects.

  • Early notifications proactively inform customers of their blast radius.

Response
  • Org-wide policies trigger automated flows with smart defaults, as soon as a malware finding appears.

  • Response actions include: open a Jira ticket, Slack SecOps, rescan to confirm removal. 

Prevention
  • Malware firewall (in private beta) stops malicious packages before they reach developer machines.

  • Built into Guardian, firewall is invisible to developers, stops malware during code generation, and is easily deployed org-wide in hours.

Supply Chain Security in the Era of Package Compromises

Last year, we introduced malicious dependency detection as the first step toward helping teams navigate package compromises. Since then, supply chain attacks have continued to increase in frequency, intensity, and scale. In Q2 of 2026 alone, it is estimated that there were 1.8 million malicious packages abusing the trust model of popular package ecosystems. In the era of open source exploits, AppSec teams are forced to cobble together disparate tools, creating friction in response to malicious and compromised dependencies. 

Today we’re announcing the introduction of Malware Detection and Response Automation as an integral part of Semgrep Supply Chain, helping organizations guard against malicious dependency-induced malware.

Zero-Day Incident Detection 

When news of a supply chain attack breaks, security teams everywhere are left wondering if their organization has been impacted. At this point, Slack channels and meeting rooms are filled with executives, security leaders, IT personnel, and developers asking “Are we impacted?”. 

Within minutes of a major supply chain incident, our 24/7 on-call security monitoring updates the Semgrep malware database with AI-assisted, expert-verified rules. We then scan—using only the newly added Advisories—across all customer repositories, to quickly tell us which projects are impacted. Customers who have opted in are proactively notified by Semgrep, via slack or webhooks. We also post an advisory on the Semgrep dashboard, visible to all customers.

Enabling early notifications allows Semgrep notify you about supply chain incidents and whether or not your projects are affected.

Zero-day Incident Detection also describes the blast radius for each affected customer. The dashboard shows the newest real incident, affected package summary, matching projects, findings, scan progress, advisory links, and incident findings.

With Semgrep, you're not finding out about an incident from your CISO and scrambling to react . Nor do you need to sort through hundreds of repositories and dependencies trying to grasp the scope of impact. Instead, everything is checked automatically. Any findings are organized by advisories, which are rolled up into actual incidents.

Org-Wide Response Automation 

Even as detection makes exposure to the supply chain attack clear, the response layer allows teams to turn that information into action. With enterprise-grade policies, practitioners can define automated responses across their entire org—auto-open a Jira ticket, fire a Slack alert, or hit a webhook into their own IR tooling—the moment a finding is generated.

Supply Chain policies allow practitioners to define automated responses to malware findings.

For AppSec teams covering hundreds of repos, this automation can mean the difference between hours and days.

What’s Next: Malware Firewall 

We would be remiss if we didn’t mention that, complementing Malware Detection and Response Automation, we are also putting the finishing touches on a Malware Firewall (in private beta) that blocks malware from reaching developer machines in the first place. 

Embedded in Semgrep Guardian, the malware firewall blocks malicious packages within the code generation environment itself, preventing execution of malware contained within malicious dependencies, without requiring any changes to development processes. Sitting between the package manager and any public package registry, the malware firewall intercepts and examines dependency requests at the network level and, based upon the verdict rendered by the malware firewall backend, allows or rejects the request accordingly.

Semgrep Malware Firewall runs silently in Guardian via Agent admin. No per-device install.

Unlike network-layer firewalls that are cumbersome to install and manage, and that add friction to the development process, the Semgrep malware firewall is easy to deploy across all machines where development work is done and doesn’t require developers to change anything about how they work while receiving automatic protection from known malicious packages.

Get Started

With Malware Detection and Response Automation, a zero-day goes from “we heard about an incident, and are trying to find out if and how we’re affected” to “Semgrep flagged the incident, scanned our environment, comms went out, and tickets were assigned," all with no human in the loop.

These capabilities are available today, to every Semgrep Supply Chain customer. Log in to try it out.