End-to-end Malware Incident Protection

Detect, respond to, and block open source supply chain attacks.

Quickly alert teams of zero-day incidents

24/7 on-call security monitoring triggers incident-specific scans within minutes of an open-source package compromise. Semgrep rapidly identifies blast radius, and proactively notifies impacted customers via dashboard, Slack or API.

Automate incident response with org-wide policies

Malware findings can be linked to automated workflows with smart defaults—including blocking commits, notifying sec-ops, re-scanning to confirm malicious dependency removal—for org-wide autonomous incident response.

Block malicious packages before they reach dev machines

Semgrep Malware Firewall runs silently on developer machines, intercepting network requests to any public registry and blocking malicious and compromised open-source packages from reaching your environment.

Award-Winning Support

Dedicated in-house support and security research teams monitor for incidents, and provide real-time product updates and response guidance.

SEMGREP THREAT FEED

Rust crates arrayref & append-only-vec compromised via malicious proc-macro1 dependency
Miasma v3 Hit 4 AsyncAPI Packages — Did NPM's Defenses Work, or Just Get Dodged?
Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages
Not Your IPC, but node-ipc: npm Hit Again with Supply Chain Attack (But This Time It's Not a Worm)
It’s not npm-ver yet: NPM worm Chaindrop hits 400+ packages including jaredwray, servicetitan, ornikar, qlik and nebula.js
TanStack Router Packages Hit by Mini Shai-Hulud TheBeautifulSandsOfTime Supply Chain Attack
Sha1-Hulud: The Second Coming of the NPM Worm is Digging For Secrets
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
SAP Cloud Build Tool Packaged A Mini Shai-Hulud Malicious Dependency That Uses Bun
RIP post/preinstall scripts: An obituary for the npm feature only TeamPCP will miss
Mini Shai-Hulud Resurfaces; Compromised Maintainer of antv, timeago, and size-sensor Packages Revives Worm Activity
Forking Shai-Hulud: RedHat npm Packages Are The Next Victim After GitHub Actions Compromise and Worm
Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin
Children of Shai-Hulud: An Analysis of the The Evolution, Delivery and Spread of the TanStack Shai-Hulud Campaign
🚨 Popular GitHub Action tj-actions/changed-files is compromised
Security Alert | chalk, debug and color on npm compromised in new supply chain attack
Security Alert | NX Compromised to Steal Wallets and Credentials
Security Advisory | NPM Packages Using Secret Scanning Tools to Steal Credentials
Remote Code Execution Security Bug in React Server Components Patched
New React2Shell Offspring Patched: React Server Components (DoS) and Source Code Exposure
New Sandbox Escape Affecting Popular nodejs Sandbox library vm2
Hackers Supply Chain Attack Moves From npm to PyPI as Trivy Breach Extends into LiteLLM Package
Security Advisory: $foo compromised on $packagemanager
Axios Supply Chain Incident: Indicators of Compromise