# Chainsaw: block malicious installs before download

> An install-path firewall that decides locally, before a package downloads. Blocks malicious code and typosquats like the xz backdoor. Free, open source.

Source: https://chain305.com/

---

Install-path firewall · open source

# Block malicious packages before they download.

$ curl \-fsSL https://chain305.com/install.sh | bash

Installs the CLI and turns the guard on · no account · works offline · [what it sends](https://chain305.com/legal/privacy/)

[Enforce it for the team →](https://chain305.com/solutions/appsec) [See it refuse ↓](#how-it-works)

  

Real refusal, real product · captions available

Named incidents

## Refuses the attack classes behind the incidents you've read about.

-   [Shai-Hulud](https://chain305.com/product/policy/#publish-velocity-bursts)
-   [PhantomRaven](https://chain305.com/product/policy/#install-script-exfiltration)
-   [GlassWorm](https://chain305.com/product/policy/#hidden-characters)
-   [Axios v1.14.1](https://chain305.com/product/policy/#maintainer-takeover)
-   [Chalk / debug (2025)](https://chain305.com/product/policy/#version-cooldown)
-   [event-stream (2018)](https://chain305.com/product/policy/#install-script-exfiltration)
-   [eslint-scope (2018)](https://chain305.com/product/policy/#maintainer-takeover)
-   [ua-parser-js (2021)](https://chain305.com/product/policy/#install-script-exfiltration)
-   [xz-utils (2024)](https://chain305.com/product/policy/#maintainer-takeover)
-   [Birsan dep-confusion (2021)](https://chain305.com/product/policy/#dependency-confusion)
-   [coa / rc typosquats (2021)](https://chain305.com/product/policy/#typosquat-detection)

How the local guard works

## One shell hook. Every decision on your machine.

1.  01 · You, or your coding agent
    
    `npm install crossenv`
    
    npm, pip, cargo, gem, go
    

3.  02 · chainsaw guard, on this machine
    
    -   typosquat distance
    -   known-malicious index
    -   package bytes, when on disk
    
    shell hook · no daemon · works offline
    

5.   Refused
    
    typosquat of "cross-env" · nothing downloaded
    
     Allowed
    
    fetched from the registry as usual
    

Real output · reproduce it offline in 30s

```
$ npm install crossenv
chainsaw  offline known-malicious + typosquat active (231875 malicious packages indexed)
chainsaw  ✗ blocked  npm:crossenv — looks like a typosquat of "cross-env" (distance 1, edit-distance, target rank #1931)
chainsaw  ✗ refused at the install path — nothing was installed
```

-   **No daemon.** A shell hook for npm, pip, cargo, gem and go.
-   **Works offline.** Malicious and typosquat seeds ship inside the binary.
-   **Readable.** The engine is open source at github.com/chain305/chainsaw-core.

How it fires

## One signed Rego policy. Five surfaces.

The pull request, the install path, publish, Kubernetes admission and your laptop read the same rule. The PR check sees only the manifest diff, so byte-level rules wait for the install.

Policy

One signed Rego policy bundle

The same rule at every surface below.

1.  01 · Pull request
    
    GitHub Action / chainsaw pr-scan
    
    Fails the check on the dependency diff. Coordinate only: CVSS and malware rules apply from install on.
    
2.  02 · Install path
    
    npm / PyPI / Maven / NuGet / Docker + 12 more
    
    Refuses the fetch, with the reason and the exception path.
    
3.  03 · Publish
    
    Hosted repo upload
    
    Refuses an upload from your own build that fails policy.
    
4.  04 · K8s admission
    
    Validating webhook
    
    Refuses the pod when the image fails the same Rego.
    
5.  05 · Laptop
    
    Local guard install hook / MDM
    
    Refuses on the developer's machine, even where the proxy was bypassed.
    

Evidence

One signed audit row

carries every refusal, wherever it happened.

Who it's for

## Same guard. Four jobs.

   

### Developers

Typosquats and malicious updates are refused before they touch your disk.

-   **“Builds get slower.”** Repeat installs serve from Chainsaw's cache. CI usually gets faster.
-   **“I can't debug a block.”** The error names the rule, the reason and the exception reviewer.
-   **“A new rule breaks me.”** Ask for new rules in monitor first. The audit log records what would have been blocked.

[See how →](https://chain305.com/solutions/developers/)

### AppSec

A CVE drops, you push one policy edit, and that version stops installing everywhere.

-   **Refuse bad packages on the install path.** Vulnerability, license and version rules plus 25 supply-chain signals beyond CVE run before a package enters a build. Depth varies by ecosystem.
-   **Cut the exposure window.** One policy edit rolls out in minutes, with no upgrade PR needed to halt new spread.
-   **Give devs a useful error.** The refusal names the rule, the reason and who owns the exception path.

[See how →](https://chain305.com/solutions/appsec/)

### DevSecOps

The same license, version and provenance rules in CI, on laptops and in Dockerfiles.

-   **Model your policy once.** License, version and provenance rules. One policy for CI, laptops and Dockerfiles.
-   **Watch monitor-mode traffic.** Every install gets a verdict in the audit log. Nothing breaks.
-   **Export evidence on demand.** CycloneDX SBOMs per repo. Audit logs stream to Splunk HEC, Microsoft Sentinel or IBM QRadar on Enterprise.

[See how →](https://chain305.com/solutions/devsecops/)

### Enterprise IT

One baseline for every org, on SaaS, in your VPC or air-gapped. Same binary.

-   **Stand up one instance.** Managed SaaS, your cloud or air-gapped. Same binary, same API.
-   **Publish the policy centrally.** One org-wide policy for vulnerabilities, licenses, provenance and supply-chain signals.
-   **Scope rules by repository.** Target a rule at specific repositories. Exceptions carry an expiry and optional two-person approval.

[See how →](https://chain305.com/solutions/enterprise-it/)

Run it for the org

## Policy at the registry, even on laptops without the CLI.

Put the proxy between your developers and the upstream registries. One signed policy, and one signed audit row for every decision.

Surface

Ecosystems

Reaches

Local guard free

5 npm, pip, cargo, gem, go

the machine it is installed on

Registry proxy

16 the five above plus Maven, Composer, NuGet, Hugging Face, CocoaPods, Swift, pub, Docker, APT, yum, DNF

every machine that installs through it, CLI or not

![Chainsaw report showing policy violations grouped by owning team.](/demo/threats-stopped.png?v=4)

Report Refusals grouped by the team that owns the repository. Demo org seeded with synthetic install traffic.

Runs as managed SaaS, in your VPC (your Postgres, blob store and audit logs; no inbound connection from us) or air-gapped with `CHAINSAW_OFFLINE=1`, sideloading intelligence on your own cadence. SSO and SCIM are on Team; SIEM export and on-prem are Enterprise; the audit trail ships on every plan. [Deployment models →](https://chain305.com/security/) [Procurement kit →](https://chain305.com/security/procurement/)

Compared to the alternatives

## More than a registry. Not a scanner.

Registries store packages and scanners report on them. Neither decides on the install path.

More than a registry

vs Cloudsmith · JFrog · Nexus · Verdaccio

-   Sits in front of the registry you already have. Nothing to migrate.
-   Refuses on the install path. A cache does not decide what is safe.

[Read the full diff →](https://chain305.com/vs-artifact-managers/)

Not a scanner

vs Snyk · Sonatype · Mend

-   Refuses before bytes land, not in a PR comment after the fact.
-   Enforced org-wide, not an opt-in CLI per developer.

[Read the full diff →](https://chain305.com/vs-sca/)

Objections, handled

## Common questions

Do I need an account? 

No. The guard runs with no account and no server. Sign in only to share one policy across a team.

Is it actually free? 

Yes. The local guard and all 25 detection signals are free. The guard runs the checks that need no network; the rest run on the hosted proxy, also free. Paid plans add the team control plane: shared policy, dashboards, SSO and SIEM.

Will it break my installs or CI? 

Start in monitor mode. Every rule logs what it would have blocked before you switch it to enforce.

What happens if Chainsaw goes down? 

Degraded data fails open by default, and the gap is written to the audit trail. Set CHAINSAW\_COVERAGE\_MODE=closed and name the sources you treat as mandatory, and it refuses anything it could not check against them.

Two commands, local, free

## Run it, then try to break it

No account needed. Paste two lines, then try npm install crossenv.

[Install the guard](https://chain305.com/quickstart) [Read the source](https://github.com/chain305/chainsaw-core)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Install-path firewall · open source

### Block malicious packages before they download.

One command turns it on. Every npm, pip, cargo, gem, and go install then gets checked against 25 supply-chain signals, and the malicious or typosquatted ones are blocked before the download even starts.

$ curl -fsSL https://chain305.com/install.sh | bash

Paste that one line and your installs are checked locally from here on, in every new terminal, before anything downloads. It installs the CLI and turns the guard on (set `CHAINSAW_NO_GUARD=1` on the `bash` side to skip that; CI skips it automatically). Then turn your wifi off and run `npm install crossenv` (a known typosquat of cross-env). It still refuses.

It runs on your own machine, and it is open source. It asks once before sharing anonymous usage (defaults to yes; decline anytime with `chainsaw telemetry off`; never from CI).

[Enforce it for the team →](https://chain305.com/solutions/appsec)

Real output · reproduce it offline in 30s

```
$ npm install crossenv
chainsaw  offline known-malicious + typosquat active (231875 malicious packages indexed)
chainsaw  ✗ blocked  npm:crossenv — looks like a typosquat of "cross-env" (distance 1, edit-distance, target rank #1931)
chainsaw  ✗ refused at the install path — nothing was installed
```

See it block

#### Watch it block a typosquat

Turn the guard on with one line in your shell. After that a normal npm install gets checked first, and a typosquat gets refused before the package downloads. The bad tarball never lands on disk.

$ eval "$(chainsaw guard init zsh)"

chainsaw: guard active for npm, pip, cargo, gem, go

$ npm install crossenv

chainsaw offline known-malicious + typosquat active (231875 malicious packages indexed)

chainsaw ✗ blocked npm:crossenv — looks like a typosquat of "cross-env" (distance 1, edit-distance, target rank #1931)

chainsaw ✗ refused at the install path — nothing was installed

Refused before download. Run chainsaw why for the full signal trace.

What just happened

1.  The installer made it permanent: its last step runs `chainsaw guard init --install`, which writes the hook into your shell rc (or turn it on for just this shell with `eval "$(chainsaw guard init zsh)"`). It adds no background daemon and never repoints your registry.
2.  You run a normal `npm install`, the same way you always do.
3.  Chainsaw reads the package against the 25 signals it weighs, including the typosquat match you see here.
4.  It refuses the install _before_ the package downloads or runs.
5.  The reason is logged on your machine, so you know why it stopped.

Named incidents

#### Refuses the attack classes behind the incidents you've read about.

-   [Shai-Hulud](https://chain305.com/product/policy/#publish-velocity-bursts)
-   [PhantomRaven](https://chain305.com/product/policy/#install-script-exfiltration)
-   [GlassWorm](https://chain305.com/product/policy/#hidden-characters)
-   [Axios v1.14.1](https://chain305.com/product/policy/#maintainer-takeover)
-   [Chalk / debug (2025)](https://chain305.com/product/policy/#version-cooldown)
-   [event-stream (2018)](https://chain305.com/product/policy/#install-script-exfiltration)
-   [eslint-scope (2018)](https://chain305.com/product/policy/#maintainer-takeover)
-   [ua-parser-js (2021)](https://chain305.com/product/policy/#install-script-exfiltration)
-   [xz-utils (2024)](https://chain305.com/product/policy/#install-script-exfiltration)
-   [Birsan dep-confusion (2021)](https://chain305.com/product/policy/#dependency-confusion)
-   [coa / rc typosquats (2021)](https://chain305.com/product/policy/#typosquat-detection)

How the local guard actually works

#### One hook in your shell. Every decision made on your machine.

-   A shell hook, not a daemon.
    
    chainsaw guard init --install wires into npm, pip, cargo, gem, and go, so installs get checked the moment you run them — no background service, no registry repoint. Your clean installs and lockfiles stay on disk. The only thing it ever shares is a package it blocked, and only after it asks you once.
    
-   Seeds ride inside the binary.
    
    Known-malicious packages and typosquats are matched against data shipped in the binary itself, so the check runs with the network unplugged.
    
-   Telemetry is a separate switch — and it asks first.
    
    First run asks once, defaulting to yes, and shows exactly what it would share before you answer. It stays silent in CI, and chainsaw telemetry on|off flips it whenever you want.
    
-   The engine is readable, and all 25 signals are free.
    
    The policy logic lives in the open at github.com/chain305/chainsaw-core. All 25 detectors run on the free tier — not a reduced set. The guard on your laptop runs the ones that work without a network (typosquat, known-malicious, and package bytes when they are on disk); the rest need registry metadata, so they run server-side, and that tier is free too.
    

How it fires

#### One signed Rego policy, checked at five surfaces against the same input.

The same policy runs on the pull request, on your laptop, on every install your CI pulls through the proxy, on publish to your internal repo, and at Kubernetes admission. That includes the install your coding agent fires on its own, because it rides the same path. One rule to write, and it meets the same input shape everywhere. The pull request is the thinnest of the five: it reads a manifest diff, so a rule that keys on a CVSS score or a malware verdict has nothing to read there and waits for the install.

-   left-pad@1.3.1
    
    ci · npm
    
    REFUSED
-   cryptography==42.0.0
    
    dev · pip
    
    MONITOR
-   @chainsaw/sdk@2.1.0
    
    ci · npm
    
    ALLOWED
-   log4j-core@2.17.2
    
    k8s · maven
    
    REFUSED

Auto-sorting install queue · refuses on the install path

mcp · agent prompt

consulting 25 signals · signed bundle

MCP-agent prompt · consulted before install

org policy → 4 repo scopes

-   payments/\*
-   checkout/\*
-   mobile/\*
-   platform/\*

One org-wide policy · repository-scoped rules

25 supply-chain signals · live

maintainer takeover · 6dworm burst · npmhidden unicode · pipKEV-listed CVE · log4jinstall-script exfil · cipublish velocity anomalytyposquat · rqeuestssignature mismatchdeleted-author republishpost-install network callmaintainer takeover · 6dworm burst · npmhidden unicode · pipKEV-listed CVE · log4jinstall-script exfil · cipublish velocity anomalytyposquat · rqeuestssignature mismatchdeleted-author republishpost-install network call

25 supply-chain signals beyond CVE

signed audit row

-   ts2026-05-26T09:14:22Z
-   actorci@platform-eu
-   packagerequests@2.32.3
-   signalmaintainer takeover
-   verdictrefused
-   scopeBU-EU · prod

signed · ed25519 · siem-bound

One signed audit row · same export for SOC 2 + ISO 27001

Who it's for

#### Same guard. Four jobs.

##### If you write code

Malicious updates and typosquats get refused before they touch your disk.

The xz backdoor shipped as a routine update. event-stream got a new maintainer who quietly slipped in a wallet stealer. Chainsaw reads the package at install time and refuses the ones whose install script reaches for your env vars or whose name shadows a popular library by one keystroke. The block happens before download, so the bad tarball never lands on your disk and there is nothing for you to clean up. You see why it stopped, then you decide.

-   Type expresss instead of express and the guard catches the typosquat before the install even resolves.
-   It reads install scripts for the part that phones home with your env vars, the exact trick event-stream used.
-   When a maintainer goes quiet for a year and then pushes a burst of releases, that pattern is one of the 25 signals it weighs. You get all 25 on the free tier.

[See how →](https://chain305.com/solutions/developers/)

##### If you run AppSec

Cut the window between disclosure and defence. A new CVE drops, you push one policy edit, and the affected version stops installing everywhere. No coordinated upgrade PRs. Supply-chain attacks SCA misses, like install scripts, maintainer takeover, and worm bursts, run on the same path.

-   Block on any of four scoring systems, and CVSS is never forced on you as the default.
-   All 25 signals on every tier, including the ones SCA tools quietly omit on free.
-   The audit row records who overrode a block and why, so the post-incident review already has its answer.

[See how →](https://chain305.com/solutions/appsec/)

##### If you own DevSecOps or Compliance

Policy runs on the install path, and the evidence lands in the dashboard. The same license, version, and provenance rules apply in CI, on laptops, and in Dockerfiles. Audit trails export straight to SOC 2, ISO 27001, and HIPAA reviews without a separate collection step.

-   The SBOM auditors actually accept. Generated at install time, not stitched together at audit time.
-   Per-tenant rules with exception expiry, so the allow-list never rots into permanent exceptions.
-   Audit logs export to Splunk, Sentinel, and QRadar in the format reviewers accept, so the follow-up questions stop.

[See how →](https://chain305.com/solutions/devsecops/)

##### If you're in Enterprise IT

One deployment, one org-wide policy set, with rules scoped by repository. Managed SaaS, your own cloud, or fully air-gapped: same binary, same API, same policy format.

-   Same binary in SaaS, your VPC, or fully air-gapped. The deployment model isn't a different product.
-   SAML, OIDC, and SCIM on Team and up. No SSO tax dressed up as a feature.
-   One org-wide policy with repository-scoped rules, and exceptions that carry an expiry and optional two-person approval.

[See how →](https://chain305.com/solutions/enterprise-it/)

Scope

#### It guards the install path. That's it.

Chainsaw checks a package the moment something tries to fetch it, then gets out of the way. Anything that sits on your install path should do one job well, so the list below stays short on purpose. What changes day to day is that bad packages stop showing up.

-   Won't read your source code.
    
    Package metadata, manifests, lockfiles. Never your repo.
    
-   Won't open PRs.
    
    Renovate and Dependabot own patch mechanics. Our decisions feed them.
    
-   Won't audit your CI.
    
    Branch protection and OIDC trust live in a CI-posture product.
    
-   Won't crawl for secrets at rest.
    
    TruffleHog and Gitleaks own that. We stop install-time exfiltration.
    
-   Won't ship a laptop agent.
    
    Hardening goes through MDM payloads (Jamf, Intune). No daemon, no kernel module.
    
-   Won't manage vendor SBOMs.
    
    TPRM platforms ingest those. We produce SBOMs for what flows through the proxy.
    

Run it for the org

#### Policy that holds at the registry, even on a laptop that never ran the CLI.

The free guard covers one developer's machine. To enforce the same checks across an org, put Chainsaw between your developers and the upstream registries. Every install hits one signed policy before the bytes download, and the block holds on machines where nobody installed the CLI. Every decision writes a signed audit row, the same row you hand an auditor for SOC 2 or ISO 27001.

Surface

Ecosystems

Reaches

Local guard free

5 npm, pip, cargo, gem, go

the machine it is installed on

Registry proxy

16 the five above plus Maven, Composer, NuGet, Hugging Face, CocoaPods, Swift, pub, Docker, APT, yum, DNF

every machine that installs through it, CLI or not

-   Managed SaaS
    
    We host the stack. HTTPS endpoint, admin URL, SSO. The lowest-effort path for teams without compliance constraints.
    
-   Your VPC (data plane on-prem)
    
    Customer-controlled Postgres, blob store, dashboard, audit logs. Vendor-managed signed-feed bundles pull one-way, with no inbound connection from us, ever.
    
-   Air-gapped
    
    CHAINSAW\_OFFLINE=1 disables every phone-home path. Sideload intelligence on the cadence your one-way diode allows. Same Rego, same audit row.
    

Install path

chainsaw-proxy · live decisions

-   @chainsaw/express@4.21.0
    
    developer · npm · cache hit · signed bundle
    
    ALLOWED
-   requests==2.32.3
    
    ci · pip · maintainer takeover · 6d old
    
    REFUSED
-   axios@1.7.2
    
    developer · npm · publish velocity anomaly
    
    INSPECTING
-   actions/checkout@v4
    
    ci · github actions · policy floor · KEV clear
    
    ALLOWED

+47 refused · maintainer takeover+12 monitor · publish velocity+3 quarantined · hidden unicode+21 refused · install-script exfil+8 allowed · KEV clear+5 refused · KEV-listed CVE+47 refused · maintainer takeover+12 monitor · publish velocity+3 quarantined · hidden unicode+21 refused · install-script exfil+8 allowed · KEV clear+5 refused · KEV-listed CVE

One audit row per install · refuses on the install path

Run it as managed SaaS, in your own VPC, or fully air-gapped. SSO and SCIM come with Team; SIEM export and on-prem/air-gapped deployment are Enterprise; the audit trail ships on every plan. [See full deployment models →](https://chain305.com/security/)

The CLI and policy engine are open source at [github.com/chain305/chainsaw-core](https://github.com/chain305/chainsaw-core). Enterprise is the hosted and self-hosted control plane on top: multi-tenant server, dashboard, SSO, and premium intelligence.

Compared to the alternatives

#### More than a registry. Not a scanner.

Most teams already run a hosted registry or an SCA scanner. Both solve real problems, but neither one runs on the install path. Chainsaw is the layer in between: a firewall on the request itself, deciding what gets through before the download starts.

More than a registry

vs Cloudsmith · JFrog · Nexus · Verdaccio

-   Sits in front of npm, PyPI, Maven, and Docker. Keep the registry you already have, since there is nothing to migrate.
-   Refuses on the install path. Caching alone doesn't decide what's safe to install.
-   One Rego rule fires at every surface (PR check, install, publish, K8s admission, runtime). A registry doesn't reach those. The PR check reads a dependency diff, so rules that need the package bytes take effect from the install path on.

[Read the full diff →](https://chain305.com/vs-artifact-managers/)

Not a scanner

vs Snyk · Sonatype · Mend

-   Refuses on install, before bytes land. It is not a comment on the PR after the fact.
-   Refuses on 25 signals SCAs miss, like install scripts, maintainer takeovers, worm bursts, hidden Unicode, and AI pickle ops.
-   Org-wide enforcement, not an opt-in CLI per developer.

[Read the full diff →](https://chain305.com/vs-sca/)

Why it exists

> I came out of the SCA vendor world. I watched customers buy the dashboard, file the tickets, and ship the vulnerable build anyway, because nothing on the market could refuse the install. Chainsaw is the layer I couldn't build there.
> 
> Zeeshan, founder

Objections, handled

#### Common questions

Do I need an account to start? 

No. The local guard installs and runs with no account and no server. \`chainsaw guard update\` pulls the full public OpenSSF malicious-packages feed directly from OpenSSF without sign-in. Sign in only when you want to sync policy across a team.

Is it actually free, or is this a trial? 

The local guard is free forever, and all 25 detection signals are free — no clock, no feature gate on detection. The guard on your machine runs the ones that need no network: typosquat, known-malicious names, and the package bytes when they are on disk. The rest need registry metadata, so they run on the hosted proxy, which is also free. The seed data ships inside the binary, so it catches known-malicious packages and typosquats offline on day one. \`chainsaw guard update\` pulls the larger public OpenSSF malicious-packages feed directly from OpenSSF. Paid plans add the hosted control plane like shared policy, dashboards, SSO, and SIEM, never the protection itself.

Will this break my installs or my CI? 

Not if you start in monitor mode. Every rule can log its decision without blocking, so you see what would have failed before you flip it to enforce. Repeat installs hit the cache, so CI usually gets faster, not slower.

How is Chainsaw different from package scanners and SCA tools? 

They report. PR-comment scanners annotate the pull request, and SCAs file dashboard findings. Chainsaw refuses on the install path, before bytes land. The same 25 signals (install scripts, maintainer takeover, worm bursts, hidden Unicode, AI pickle ops) fire on every tier including free, and the same Rego rule is evaluated at the PR check, install, publish, K8s admission, and runtime. The PR check reads a manifest diff, so rules that need the package bytes wait for the install. Run both if you want. /vs-sca/ has the per-ecosystem signal map.

How is it different from Cloudsmith, JFrog, or Nexus? 

Those host packages. Chainsaw refuses them on the install path. There is no migration: your developers keep pulling from npm, PyPI, Maven, Docker, and the rest, and Chainsaw decides which requests get through. Run both if you like. /vs-artifact-managers/ has the full diff.

Does it work with monorepos, Yarn workspaces, pnpm? 

Yes. Chainsaw proxies the registry, so your workspace layout is untouched. Turbo, Nx, Lerna, Yarn workspaces, and pnpm workspaces all work without modification.

What happens if Chainsaw itself goes down? 

Depends which part. The proxy sits in your install path, so if the process itself is down, run it HA — the deployment guide covers that. If the proxy is up but its database or a threat-intel feed is degraded, installs proceed and the gap lands in the audit trail: Chainsaw fails open by default rather than breaking your builds. If you'd rather it stopped, set CHAINSAW\_COVERAGE\_MODE=closed, name the data sources you treat as mandatory, and it blocks anything it couldn't fully check. And when an upstream registry is down, the cache keeps serving previously-allowed installs.

Can we run it on-prem or air-gapped? 

Yes, on the Enterprise plan. The CLI can bake the server URL at build time so air-gapped users never see a public origin. For custom deployments, book a 30-minute call.

Two commands, local, free

#### Run it, then try to break it

Paste two lines and your next npm or pip install gets checked locally, before anything downloads. Try npm install crossenv (a known typosquat of cross-env) and watch it stop. It is open source and free forever, and you can start without an account.

[Install the guard](https://chain305.com/quickstart) [Read the source](https://github.com/chain305/chainsaw-core)
