# Quickstart: your first block | Chainsaw

> Install the free, open-source CLI, turn on the guard, and watch it block a typosquat. Runs locally, with no account and no registry repoint.

Source: https://chain305.com/quickstart/

---

Quickstart

# Your first block, the first time you run install

Three commands, about a minute. No account, no server, no registry repoint.

[Turn on the guard →](#steps) [Scale this to a team →](#team)

1.  01
    
    ## Install the CLI
    
    ```
    curl -fsSL https://chain305.com/install.sh | bash
    ```
    
    One binary in `~/.local/bin`, no sudo. Windows: `irm https://chain305.com/install.ps1 | iex`
    
2.  02
    
    ## Turn on the guard
    
    ```
    chainsaw guard init --install
    ```
    
    The installer already did this for you, on macOS, Linux and Windows (it prints a `Guard:` line); run it only if that line says it was skipped. Hooks npm, pip, cargo, gem and go in your shell rc. Current shell only: `eval "$(chainsaw guard init zsh)"`
    
3.  03
    
    ## Watch it block
    
    ```
    npm install crossenv
    ```
    
    A typosquat of `cross-env`. Works with the network off.
    

What you'll see · real output

```
chainsaw  offline known-malicious + typosquat active (231875 malicious packages indexed)
chainsaw  ✗ blocked  npm:crossenv — looks like a typosquat of "cross-env" (distance 1, edit-distance, target rank #1931)
chainsaw  ✗ refused at the install path — nothing was installed
```

Also try: `pip install python3-dateutil` · `cargo add rustdecimal` · `gem install rest-clientt` · `go get github.com/sirupsen/logruss`

First run asks once before sharing anonymous usage (defaults to yes, never from CI). Change it with `chainsaw telemetry on|off`. [Privacy policy](https://chain305.com/legal/privacy/)

Scale this to a team

## Same block, enforced for everyone

Run Chainsaw as a proxy in front of your registries: shared policy, an audit trail, and blocks that hold on machines without the CLI.

1.  01
    
    ### Sign up
    
    Free tier, no credit card.
    
    [Start free →](https://chain305.com/chainsaw/signup)
2.  02
    
    ### Create a client credential
    
    **Access → Client credentials**. The secret is shown once.
    
    [Open client credentials →](https://chain305.com/chainsaw/settings/clients)
3.  03
    
    ### Point npm at Chainsaw
    
    ```
    npm config set registry https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/npmjs/
    ```
    
    pip or Docker instead
    
    pip / PyPI
    
    ```
    pip config set global.index-url https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/pypi/simple
    pip config set global.trusted-host chain305.com
    ```
    
    Two lines. pip needs trusted-host once credentials are embedded in the URL.
    
    Docker
    
    ```
    docker login chain305.com
    ```
    
    Username: your CLIENT\_ID. Password: your CLIENT\_SECRET.
    
4.  04
    
    ### Run the demo install
    
    ```
    npm install lodahs
    ```
    
    Refused by the seeded demo policy.
    

Next: [see the block in your dashboard](https://chain305.com/chainsaw/insights) · [16 package managers](https://chain305.com/integrations) · [book a 30-minute walkthrough](https://cal.com/chain305/30min)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Quickstart

### Your first block, the first time you run install

Install the free, open-source CLI and turn on the guard. Your existing package managers (npm, pip, cargo, gem, go) get checked at install time on your own machine, with no server and no registry repoint, blocking known-malicious packages and typosquats before they download. The first time you use it, it asks once whether to share anonymous usage and blocked-package data to improve detection (the prompt defaults to yes; decline anytime, and it never sends from CI); your clean installs never leave your machine. Change anytime with `chainsaw telemetry on|off` (see our [privacy policy](https://chain305.com/legal/privacy/)). `chainsaw guard update` pulls the full public OpenSSF malicious-packages feed directly from OpenSSF, with no account. Guard blocks are always recorded on this machine. Sign in to share one policy across your team through the registry proxy, and, with telemetry on, to have this machine's blocks appear on the dashboard alongside proxy and CI activity.

[Turn on the guard →](#steps) [Scale this to a team →](#team)

Step 1 of 3

#### Install the CLI

Free and open source. One command, no account, and no sudo. It drops a single binary in `~/.local/bin` and adds that to your PATH, so nothing touches a system directory. `chainsaw guard update` pulls the full public OpenSSF malicious-packages feed later, still with no account. Guard blocks stay on this machine unless you sign in with telemetry on; sign in to share one policy across your team through the registry proxy.

```
curl -fsSL https://chain305.com/install.sh | sh
```

On Windows, run this in PowerShell instead: `irm https://chain305.com/install.ps1 | iex`. It installs per-user under `%LOCALAPPDATA%` and updates your user PATH, so it needs no admin rights.

Step 2 of 3

#### Turn on the guard

The installer already did this on macOS, Linux and Windows: its output ends with a `Guard:` line. The shim auto-checks your existing package managers with no registry repoint and no config to maintain. If the `Guard:` line says it was skipped, one command writes it into your shell rc (idempotent — safe to run twice):

```
chainsaw guard init --install      # writes the hook to your shell rc, once

### or turn it on for the current shell only:
eval "$(chainsaw guard init zsh)"   # bash/zsh
chainsaw guard init fish | source   # fish
```

From now on, `npm`, `pip` (and `pip3`), `go`, `cargo`, and `gem` installs are checked automatically. Prefer not to touch your shell? Run one-shot: `chainsaw npm install <package>`.

Step 3 of 3

#### Watch it block

Try installing a typosquat of a package you know, like a misspelling of a popular name. The guard refuses it before it downloads, using embedded seeds, so it works with no network. Known-malicious packages (a curated floor) and typosquats of popular packages are both caught at install time.

##### npm

```
npm install crossenv
```

`crossenv` is a typosquat of `cross-env` — blocked before it downloads.

##### pip / cargo / gem

```
pip install python3-dateutil
cargo add rustdecimal
gem install rest-clientt
```

Typosquats of `python-dateutil`, `rust_decimal`, and `rest-client` — same check across Python, Rust, and Ruby.

##### go

```
go get github.com/sirupsen/logruss
```

A typosquat of `logrus` — Go modules are checked at fetch time too.

Want the full known-malicious set? Pull it once with `chainsaw guard update`. Everything still runs locally, and nothing about your installs leaves the machine.

Scale this to a team

#### Same block, enforced for everyone

The local guard is per-developer. To enforce the same checks across a team, with shared policies, an audit trail, and blocks that hold even on machines without the CLI, run Chainsaw as a proxy in front of your registries. This path needs an account and a running endpoint; the local guard above needs neither.

Team · Step 1 of 4

#### Sign up

Free tier, no credit card. The signup form takes about 30 seconds: email, org name, password. Email verification optional in dev.

[Start free →](https://chain305.com/chainsaw/signup)

Team · Step 2 of 4

#### Copy your client credentials

In your dashboard, go to **Access → Client credentials** and create a credential pair. You'll get a `CLIENT_ID` and a `CLIENT_SECRET`. Keep them handy for the next step. The secret is shown once, so copy it now.

[Open Access → Client credentials →](https://chain305.com/chainsaw/settings/clients)

Team · Step 3 of 4

#### Point your package manager at Chainsaw

One config block per ecosystem. No agent, no certificate, no MITM proxy on your network. Pick the package manager you actually use and paste your `CLIENT_ID` and `CLIENT_SECRET` from the previous step:

##### npm

Register Chainsaw as your registry:

```
npm config set registry https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/npmjs/
```

Replace CLIENT\_ID and CLIENT\_SECRET with the values you copied in step 2.

##### pip / PyPI

Register Chainsaw as your registry:

```
pip config set global.index-url https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/pypi/simple
pip config set global.trusted-host chain305.com
```

Two lines. pip needs trusted-host once credentials are embedded in the URL.

##### Docker

Register Chainsaw as your registry:

```
docker login chain305.com
```

Username: your CLIENT\_ID. Password: your CLIENT\_SECRET.

Team · Step 4 of 4

#### Run the demo install

Pick your ecosystem and run the install. The demo packages here are drawn from the OpenSSF malicious-packages feed, long-tail entries flagged for typosquatting or known malware. Chainsaw refuses each one against the seeded demo policies.

##### npm

```
npm install lodahs
```

lodahs is a known typosquat of lodash, flagged in the OpenSSF malicious-packages feed. Chainsaw refuses the install before the package is downloaded.

##### pip / PyPI

```
pip install reqeusts
```

reqeusts is a known typosquat of requests. Chainsaw blocks the install at metadata-fetch time.

##### Docker

```
docker pull chain305.com/repository/@default/docker/library/known-malicious-image:latest
```

Chainsaw checks every image pull against the OpenSSF malware feed and blocks known-bad layers before they hit your registry cache.

What you'll see in the terminal

```
chainsaw  offline known-malicious + typosquat active (231875 malicious packages indexed)
chainsaw  ✗ blocked  npm:lodahs — looks like a typosquat of "lodash" (distance 1, edit-distance, target rank #101)
chainsaw  ✗ refused at the install path — nothing was installed
```

What's next

#### Now that you've seen it block

-   [### See the block in your dashboard
    
    Open Insights → top blocked packages. Your install shows up with the matched policy and reason.](https://chain305.com/chainsaw/insights)
-   [### Edit or delete the demo policies
    
    Two demo rules ship enabled per new org: "Demo: Block known malware" and "Demo: Block suspected typosquats". Edit or delete them once you've felt them fire.](https://chain305.com/chainsaw/policies)
-   [### Doctor when something looks off
    
    Two CLI commands for when behaviour disagrees with config: chainsaw doctor verify-hook catches client-side bypasses (an .npmrc edit or env override skipping the proxy), and chainsaw doctor logs surfaces operator-actionable WARN lines from the server so you don't have to grep raw stdout.](https://docs.chain305.com/tutorials/)
-   [### Roll out across more ecosystems
    
    Chainsaw proxies 16 package managers. The full deployment guide covers npm, pip, Maven, Cargo, Docker, Swift, RubyGems, Hugging Face, and the rest. Docker per-layer inspection and Swift git-tag fallback are now on by default, with no extra config to get container depth out of the box.](https://chain305.com/integrations)

Stuck? [Book a 30-minute demo](https://cal.com/chain305/30min) and we'll walk you through it together.
