Chainguard Libraries is a malware-free catalog of language dependencies that replaces your team’s reliance on public registries. When the attack hits npm or PyPI, your engineers keep building rather than pulling apart dependency trees.
The world’s leading companies trust Chainguard
Whether it’s a malicious backdoored binary, install-time script, or typosquatted package, Chainguard Libraries are safe from the malware compromises that have made headlines over the last few months.
Nation-state actors attacked the HTTP requests package in npm that’s used 400M+ times a month.
Attackers hit a key AI gateway package in PyPI with 280M+ monthly downloads.
A worm spread through ~800 npm packages and harvested thousands of private credentials.
A typosquatted npm dependency duped @TanStack users with four malicious versions.
Attackers released malicious version of an AI project with 1.1M+ monthly downloads.
Bad actors released 18 npm packages with more than 10B+ collective monthly downloads.
Open source language ecosystems
Chainguard replaces your public registry endpoints
Turn off live access to PyPI with a full catalog of safe dependencies built, curated, and remediated by Chainguard.
Swap npm for Chainguard, removing your team’s fears that the installed package contains credential harvesting malware.
Trade Maven Central for a trusted, verified dependencies from Chainguard so your team can ship without supply chain risk.
Chainguard is building additional ecosystems based on customer demand. Have a request? Reach out to our team.
Security or dev velocity. Why choose?
Stop reacting to supply chain attacks and start preventing them. Chainguard Libraries is a malware-free catalog of open source dependencies that allows your team to ship without inheriting someone else’s security compromise.
Prevent malware by design
Stop supply chain attacks before they ever reach your environment with a safe catalog of open source packages that are built, curated, and remediated by Chainguard.
Eliminate “are we impacted?” fire drills
Avoid the incident response scramble when the attack hits so your engineers stay on roadmap work instead of pulling apart dependency trees at 2 a.m.
Remediate critical and high-severity CVEs for versions you’re stuck on so you can stay safe while you plan your major upgrade.
Works with your existing tooling
Chainguard Libraries works with your existing artifact managers and workflows. Each package has the same functionality as the public upstream version, so there are no breaking changes. Your engineers won’t notice a difference.
Every package is scanned for malicious behavior
Our software factory scans for malware and 'greyware' packages before any artifact can reach your team. With Chainguard, you don’t have an exposure window because we never build or distribute packages until they’re marked safe.
Embedded policies protect what’s not built
With the Chainguard Repository, you get every package you need on day one. Configure cooldowns and block packages that don't meet your organization's standards. Your supply chain security improves overnight.
Signed, sealed, and dependable
Every Chainguard-built version comes built with full provenance and signed SBOMs, giving you indisputable proof that your dependencies came from the SLSA L3-compliant Chainguard Factory and not a vulnerable maintainer account.
Patched critical and high CVEs in Python & Java
We backport critical and high-severity CVE fixes from upstream versions and test every remediation to ensure the issue is successfully resolved, letting you stay secure while planning your major version upgrade.
Trusted libraries you can’t get elsewhere
Proactive malware prevention
Stay protected from malicious attacks often inserted during the build and distribution stages of package creation.
Verification by default
Every library is built in a secure, SLSA L3 build system with full provenance and signed SBOMs to prove supply chain integrity.
Access to hundreds of thousands of versions of libraries across Java, Python, and JavaScript, with more being added every week.
Expertise and experience
The leading open source minds driving the industry forward, delivering new innovations for developers.
Explore the rest of Chainguard’s product suite
Introducing Chainguard Repository: A unified experience for secure-by-default open source artifacts
Registries and the npm Breach: Securing the Weakest Link in the Software Supply Chain
Malware-Resistant Python without the Guesswork
Announcing Chainguard Libraries: Guarded Java Language Dependencies Built from Source
Chainguard’s Vision for a Safer Software Supply Chain
Panic! At The Distro: A Study of Malware Prevention in Linux Distributions
Taming bad Python packages: Assessing Python malware detectors with a benchmark dataset
$ chainguard learn --more
Frequently Asked Questions
A malware-free dependency catalog is a curated repository of open source packages that's built from verified source code and protected by layered security controls. The curated repository replaces direct developer access to public registries like npm, PyPI, and Maven Central.
Public registries distribute whatever maintainers publish. While the scale is tremendous, it's impossible to distinguish which packages are safe and which contain malware without additional security tooling. That implicit trust model is how the Axios, LiteLLM, and the Shai-Hulud attacks happened this year. While a CVE wasn't exploited, developer trust in the public registry ecosystem was. A malware-free catalog breaks that assumption before a package is ever available for download.
Chainguard Libraries works in three layers. First, packages are rebuilt from source in a SLSA Level 3-compliant software factory—since 98% of malware has no verifiable source code , malware can't survive the rebuild. Second, packages pass through a configurable cooldown-protected upstream fallback that gates delivery before newly published threats can spread. Third, every package is scanned for malicious behavior before distribution.
Chainguard significantly reduces supply chain attack risk by rebuilding every library from verified source code in tamper-proof environment, preventing malicious code injection at the build and distribution stages. In testing against 3,025 known malicious Python packages from the Backstabber's Knife Collection, Chainguard's rebuilt-from-source approach successfully prevented 98% of these compromised packages from reaching users.
Chainguard also offers additional security controls such as configurable cooldowns and malicious behavior detection to further prevent any risk of malware.
Attackers often compromise the build systems where packages are compiled (injecting malicious code before publication, like the XZ-Utils backdoor) or hijack distribution by stealing developer credentials to upload malicious versions to registries like npm, PyPI, or Maven Central. Because trust is often assumed but never verified from public registries, these attacks spread rapidly through automated dependency updates before they are detected.
"Built from source" means Chainguard rebuilds every library from its original source code repository rather than downloading pre-compiled artifacts from public registries. This creates a trusted, verifiable chain of custody and eliminates the risk of consuming packages that were tampered with during the build or upload. Every library comes with with full provenance proving exactly how, when, and where it was built.
Chainguard Libraries currently supports JavaScript (npm), Java (Maven), and Python (PyPI). Additional language ecosystems are being considered based on customer demand.
Yes. Chainguard Libraries integrates with common artifact managers such as JFrog Artifactory, Sonatype Nexus Repository, and Cloudsmith. Once configured as an upstream source, developers pull trusted dependencies through your existing tools automatically, with no change to your workflows.
Every Chainguard-built package ships with Sigstore signatures (cryptographic proof of authenticity), a signed SBOM (complete inventory of components), and SLSA Level 3 provenance (attestation documenting how and where it was built). These attestations let you verify the origin and integrity of every package, ensuring no tampering occurred between source code and consumption.
No. Libraries appear as just another upstream repository (just like PyPI, npm, Maven Central, NuGet), so developers can use Chainguard Libraries without any operational change. That means your builds and environments work as the same as before—just with signed, verified packages. No new tooling required.
Chainguard backports upstream fixes for critical and high-severity CVEs in popular and highly request Python libraries. This allows you to stay protected while you plan your version upgrade, eliminating the pressure to immediately migrate to the latest version just to address security issues.
Yes. Chainguard Libraries can be used standalone in any environment (developer machines, CI/CD pipelines, or production) where your code is developed and deployed. However, combining Libraries with Chainguard Containers or VMs provides complete protection across your entire stack, from OS to application dependencies.
FIPS is offered with Chainguard Containers (and related hardened variants), not as a feature of Chainguard Libraries. Use Libraries for the secure dependencies and pair them with FIPS containers/VMs when FIPS-validated cryptography is required.
SLSA (Supply-chain Levels for Software Artifacts) Level 3 is an industry-standard framework that requires builds to be performed on hardened infrastructure with automated provenance generation and additional guarantees that the build platform itself is trustworthy and tamper-resistant. This ensures packages are built in a fully auditable environment where even the build system cannot be compromised. For libraries, this means you get cryptographic proof that each package was built from verified source code without compromise, and that the build environment itself has been hardened against insider threats and infrastructure-level attacks. This prevents supply chain attacks at the build and distribution stages where attackers often inject malicious code.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
