Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

npm Dependency Firewall

A trusted npm dependency can become risky with a single new release. Bytesafe blocks malware, packages with known vulnerabilities and policy violations before they reach your build. New releases can also be delayed, reducing exposure before malicious packages or vulnerabilities are identified.

Dependency Firewall sits in front of your existing repository, protecting developers, CI/CD pipelines and AI agents.

EU-based company · Software supply chain security since 2018.

Logs

Firewall npm-ci
StatusPackageRule
AllowedminimistException
BlockednxDelay 7 days
BlockedlodashBlock CVSS ≥ 7
AllowedexpressLog all downloads
Blockedevent-streamKnown malware
AllowedreactLog all downloads

Intercepts every npm package request before it reaches you.

Every package install is a potential entry point. Traditional SCA tools find problems after packages are already in your environment. Dependency Firewall intercepts every npm request before it reaches your developers, CI/CD pipelines or AI agents.

You define the rules: block packages with known CVEs, block known malicious packages, or delay newly published versions for a configurable period to give the ecosystem community time to surface zero-day threats.

Works in front of enterprise repository platforms and any npm registry. No agent installs. No workflow changes.

Public npm registry

Vulnerable and malicious versions included

Risky packages
Bytesafe

Dependency Firewall

Policy engine
Vetted packages only

Developers and CI/CD

Internal environment

What Dependency Firewall does for npm

Each firewall runs the checks you turn on, on every package request. Rules block or log, and every decision is recorded.

Malware blocking
Blocks packages that match malware data, including malicious payloads and suspicious install hooks. Every block is logged with the package and the rule.
Vulnerability blocking
Blocks versions with CVEs above a CVSS or EPSS score you set, per firewall. New advisories apply on the next request.
Package delay
Holds newly published versions for a window you set, so malware feeds can catch a bad release before your builds install it.
Time-limited exceptions
Unblock one package or version with a reason and an expiry date. The rule keeps applying to everything else, and the exception lapses on its own.
Dependency confusion
Upstream priority rules make internal package names always resolve from your private registry. A public package with the same name cannot take its place.
Package observations
Every package that passes records first-seen and last-seen time and request counts. When a new advisory lands, you see which firewalls served the package and since when.
Audit log
Every allow, block and exception is logged with the package, version, rule, requester and time. Export it to your SIEM.

Dependency Firewall offer

Half the base fee for your first 3 months

€49.50 instead of €99 per month, plus €100 usage credit. Start with a 14-day trial, no card required. See what's new

How npm installs go through the firewall

Your package manager asks the firewall instead of the public registry. The firewall fetches the package from upstream, checks it against your rules and serves it only if it passes.

  1. 1

    Change the registry setting

    Point npm, Yarn, pnpm or Bun at the firewall, on laptops and CI runners. Lockfiles, manifests and install commands stay the same.

  2. 2

    Set the rules

    Block by CVSS or EPSS score, known malware, license or package age. Shared rules go on a baseline firewall that team and CI firewalls inherit, and they run first.

    Rules on a firewall: block downloads with CVSS above 7, log all downloads, and a 7-day delay inherited from npm-baseline
    Rules on the npm-ci firewall. The 7-day delay is inherited from npm-baseline.
  3. 3

    Read the log

    A version held back by a rule is left out of the version list, so the package manager resolves an older one. A blocked download fails the install. Every decision is logged with the rule and who asked.

    Firewall log: lerna, nx and js-yaml versions blocked by the 7-day delay, other packages allowed
    New versions held by the delay rule, next to allowed downloads.

Configure your npm proxy in one command

Point npm, yarn, pnpm or Bun at your Bytesafe Dependency Firewall endpoint. Existing package manager commands and lock files continue to work without changes.

Works with the repositories you already use

JFrog Artifactory
Sonatype Nexus
GitLab
GitHub Packages
Azure Artifacts
AWS CodeArtifact

Inside Dependency Firewall

The screens your developers and security team work with.

1 of 7 · Logs

Live firewall logs

Every request is logged: package name, version, status, ecosystem, which firewall evaluated it, which rule triggered and who requested it. Filter by firewall or user, and tail live during incidents or CI/CD runs.

Developers get a fast answer when an install fails, and AppSec gets an audit trail for every decision.

Live request log with blocked packages and rule details
Live request log with blocked packages and rule details

Known attacks on npm

Malicious releases, account takeovers and dependency confusion have all been used against packages there.

shai-hulud

Worm

A self-spreading worm stole npm tokens from developers who installed an infected version, then used them to publish infected versions of those developers' own packages. Hundreds of packages were hit, and a second wave followed in November 2025.

ua-parser-js

Account takeover

An attacker gained access to the maintainer's npm account and published three malicious versions. The injected payload installed a cryptominer and a credential-stealing trojan. Over 8 million weekly downloads at the time.

event-stream

Maintainer handoff

A maintainer transferred ownership to an unknown account. The new maintainer injected code that stole Bitcoin wallet keys from a specific Copay application. The package had 2 million weekly downloads.

colors.js / faker.js

Maintainer sabotage

The maintainer published versions that caused applications to print infinite ANSI sequences and nonsense strings to stdout. Thousands of applications broke on upgrade without any warning.

Also blocks vulnerable and malicious container images before they reach a build agent or production node.

Container Dependency Firewall

Compared with other enterprise dependency firewalls

Other enterprise dependency firewalls are often bundled into repository platforms. Dependency Firewall is an independent firewall that works with any registry and is built in the EU.

CriterionDependency FirewallOther enterprise firewalls
Works with your existing repositoryYes, as a proxy in front of itBundled into their platform most often
Deploys in minutesYesUsually weeks of platform work most often
Predictable pricingOne meter sets the price, no overageSeveral axes with overage most often
EU data residencyYesNo, US-based most often

Frequently asked questions

How do I configure npm to use Bytesafe Dependency Firewall?
Run `npm config set registry https://registry.bytesafe.dev/r/<firewall-id>/` with your firewall ID from the Bytesafe dashboard. Yarn, pnpm and Bun support the same approach via their respective config files. See docs.bytesafe.dev for step-by-step instructions.
Does it work with private npm packages?
Yes. Bytesafe Dependency Firewall can proxy multiple upstreams. Configure it to serve your private registry for scoped packages and npm for public ones. Private packages always resolve first, which also prevents dependency confusion attacks.
Will it break my existing package-lock.json or yarn.lock?
No. Bytesafe Dependency Firewall is a transparent proxy. It serves the same package metadata and tarballs as npm. Your lock files remain valid and installs continue to be reproducible.
Does the zero-day safety delay apply to all npm packages?
You configure which rules apply. You can delay all new versions, or only versions from packages that have never been seen in your organization before. Rules can target specific package name patterns or version ranges.
Can different npm projects have different policies?
Yes. You can create separate firewalls per project. They are lightweight and easy to clone. You can also differentiate by the user or token used for the session. Firewall configurations are small JSON files that can be managed in Git.
Can npm packages be delayed before they reach developers?
Yes. Dependency Firewall can hold newly published package versions for a window you configure before they reach developers or pipelines. Centralizing delay rules means the protection applies automatically across all teams and pipelines without each project configuring it separately.
What happens if a npm package passes through but malware is found later?
The firewall tracks all packages via observations: first-seen date, last-seen date, and which firewalls they passed through. When new malware data surfaces, you can see exactly which projects downloaded the affected package and when.
Can firewall rules be automated?
Yes. All configuration is available via API. Configurations can be version-controlled in Git and deployed through your existing automation. All changes are tracked with full rollback support.
Does Dependency Firewall work with enterprise repository platforms?
Yes. Dependency Firewall speaks the same protocols as your package managers, so it is fully transparent to enterprise repository platforms and package registries, including JFrog Artifactory, Sonatype Nexus, GitLab, GitHub Packages and Azure Artifacts.
How is licensing structured?
Two plans: Cloud for SaaS and Enterprise for custom deployment, Managed Cloud or On-Premise. Cloud is priced on whichever you use most: active users, packages scanned or downloads served. See pricing for plan details and add-ons.

Bytesafe Platform

Software Supply Chain Security and Transparency

Three products that block risky packages at install, collect supplier transparency documents, and analyze them.

Put npm installs behind the firewall

Try the setup above on one project and check the firewall log after the next install. Or book a demo and go through your registries and rules with an engineer.

Book a Demo