Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
safe-chain — Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required. | Kitploit
ツール/GitHubGitHub/aikidosec/safe-chain
Defensive ToolsVulnerability ScannersMalware AnalysisDevSecOpsThreat IntelligenceSupply Chain Security
GitHubaikidosec/safe-chain

safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

リポジトリを見る
1.7k106317時間40分前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ウェブサイト
要求された言語のコンテンツは利用できません。英語版を表示しています。

Aikido Safe Chain

Aikido Safe Chain

NPM Version NPM Downloads

  • ✅ Block malware on developer laptops and CI/CD
  • ✅ Supports npm and PyPI more package managers coming
  • ✅ Blocks packages newer than 48 hours without breaking your build
  • ✅ Tokenless, free, no build data shared

Need protection beyond npm & PyPI?

Aikido Device Protection builds on Safe Chain, extending package and extension security across more ecosystems: npm, PyPI, VS Code, Open VSX - (Cursor, Windsurf, Kiro, Vs Codium, ...), Maven, NuGet, Chrome extensions, Go, Skills.sh AI skills, Ruby, Rust, and more.

Get centralized policy management, request-and-approval workflows, and visibility across every developer workstation in your org. Powered by the same Aikido Intel feed. Deploy it manually or manage it through your MDM tool (Jamf, Fleet, or Iru).


Aikido Safe Chain supports the following package managers:

  • 📦 npm
  • 📦 npx
  • 📦 yarn
  • 📦 pnpm
  • 📦 pnpx
  • 📦 rush
  • 📦 rushx
  • 📦 bun
  • 📦 bunx
  • 📦 pip
  • 📦 pip3
  • 📦 uv
  • 📦 poetry
  • 📦 uvx
  • 📦 pipx
  • 📦 pdm

Usage

Aikido Safe Chain demo

Installation

Installing the Aikido Safe Chain is easy with the installation script.

Unix/Linux/macOS

curl -fsSL https://github.com/AikidoSec/safe-chain/releases/download/1.5.23/install-safe-chain.sh -o /tmp/install-safe-chain.sh \
  && echo "b7eac1c7152f300b229b865193d16424ad52386d1898c75ffaf374fcb4eeed3d  /tmp/install-safe-chain.sh" | sha256sum -c - \
  && sh /tmp/install-safe-chain.sh \
  && rm /tmp/install-safe-chain.sh

Windows (PowerShell)

$installer = Join-Path $env:TEMP "install-safe-chain.ps1"
Invoke-WebRequest "https://github.com/AikidoSec/safe-chain/releases/download/1.5.23/install-safe-chain.ps1" -OutFile $installer -UseBasicParsing
$expectedHash = "7E1274C8D9110798383A995BBA622E986D5A01C53B8FB76CC6934509EB27CFF7"
if ((Get-FileHash $installer -Algorithm SHA256).Hash -ne $expectedHash) {
    Remove-Item $installer -ErrorAction SilentlyContinue
    throw "Checksum verification failed for install-safe-chain.ps1"
}
& $installer
Remove-Item $installer

The install commands above always reference a specific release. To install a different version, replace the version with your desired version number. All available versions are on the releases page.

Download integrity

The install scripts are served from a versioned release URL (releases/download/1.5.23/...). GitHub releases are immutable — once an artifact is published at a versioned URL it cannot be modified or replaced, so the file you download is guaranteed to be exactly what was released.

Verify the installation

  1. ❗Restart your terminal to start using the Aikido Safe Chain.

    • This step is crucial as it ensures that the shell aliases for npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, pip, pip3, poetry, uv, uvx, pipx and pdm are loaded correctly. If you do not restart your terminal, the aliases will not be available.
  2. Verify the installation by running the verification command:

    npm safe-chain-verify
    pnpm safe-chain-verify
    pip safe-chain-verify
    uv safe-chain-verify
    
    # Any other supported package manager: {packagemanager} safe-chain-verify
    
    • The output should display "OK: Safe-chain works!" confirming that Aikido Safe Chain is properly installed and running.
  3. (Optional) Test malware blocking by attempting to install a test package:

    For JavaScript/Node.js:

    npm install safe-chain-test
    

    For Python:

    pip3 install safe-chain-pi-test
    
    • The output should show that Aikido Safe Chain is blocking the installation of these test packages as they are flagged as malware.

When running npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, pip, pip3, uv, uvx, poetry, pipx and pdm commands, the Aikido Safe Chain will automatically check for malware in the packages you are trying to install. It also intercepts Python module invocations for pip when available (e.g., python -m pip install ..., python3 -m pip download ...). If any malware is detected, it will prompt you to exit the command.

You can check the installed version by running:

safe-chain --version

How it works

Malware Blocking

The Aikido Safe Chain works by running a lightweight proxy server that intercepts package downloads from the npm registry and PyPI. When you run npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, pip, pip3, uv, uvx, poetry, pipx or pdm commands, all package downloads are routed through this local proxy, which verifies packages in real-time against Aikido Intel - Open Sources Threat Intelligence. If malware is detected in any package (including deep dependencies), the proxy blocks the download before the malicious code reaches your machine.

Minimum package age

Safe Chain applies minimum package age checks to supported ecosystems.

Current enforcement differs by ecosystem:

  • npm-based package managers:
    • during normal package resolution, Safe Chain suppresses versions that are newer than the configured minimum age from the package metadata returned by the registry
    • for direct package download requests that bypass that metadata flow, Safe Chain can block the request itself using a cached list of newly released packages
  • Python package managers:
    • during package resolution, Safe Chain suppresses too-young files and releases from PyPI metadata responses
    • for direct package download requests that bypass that metadata flow, Safe Chain can block the request itself using a cached list of newly released packages

By default, the minimum package age is 48 hours. This provides an additional security layer during the critical period when newly published packages are most vulnerable to containing undetected threats. You can configure this threshold or bypass this protection entirely - see the Minimum Package Age Configuration section below.

For urgent CVE fixes, Aikido confirms the patch release is free of malware and Safe Chain exempts it from the minimum age check, so you're not left exposed to the vulnerability it fixes while waiting out the window.

Shell Integration

The Aikido Safe Chain integrates with your shell to provide a seamless experience when using npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, and Python package managers (pip, uv, uvx, poetry, pipx, pdm). It sets up aliases for these commands so that they are wrapped by the Aikido Safe Chain commands, which manage the proxy server before executing the original commands. We currently support:

  • ✅ Bash
  • ✅ Zsh
  • ✅ Fish
  • ✅ PowerShell
  • ✅ PowerShell Core

More information about the shell integration can be found in the shell integration documentation.

Uninstallation

To uninstall the Aikido Safe Chain, use our one-line uninstaller:

Unix/Linux/macOS

curl -fsSL https://github.com/AikidoSec/safe-chain/releases/download/1.5.23/uninstall-safe-chain.sh | sh

Windows (PowerShell)

ツールをダウンロード