Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
safe-chain — Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required. | Kitploit
도구/GitHubGitHub/aikidosec/safe-chain
Defensive ToolsVulnerability ScannersMalware AnalysisDevSecOpsThreat IntelligenceSupply Chain Security
GitHubaikidosec/safe-chain

safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

저장소 보기
1.7k1063216시간 29분 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Aikido Safe Chain

Aikido Safe Chain

NPM Version NPM Downloads

  • ✅ Block malware on developer laptops and CI/CD
  • ✅ Supports npm and PyPI more package managers coming
  • ✅ Blocks packages newer than 48 hours without breaking your build
  • ✅ Tokenless, free, no build data shared

Need protection beyond npm & PyPI?

Aikido Device Protection builds on Safe Chain, extending package and extension security across more ecosystems: npm, PyPI, VS Code, Open VSX - (Cursor, Windsurf, Kiro, Vs Codium, ...), Maven, NuGet, Chrome extensions, Go, Skills.sh AI skills, Ruby, Rust, and more.

Get centralized policy management, request-and-approval workflows, and visibility across every developer workstation in your org. Powered by the same Aikido Intel feed. Deploy it manually or manage it through your MDM tool (Jamf, Fleet, or Iru).


Aikido Safe Chain supports the following package managers:

  • 📦 npm
  • 📦 npx
  • 📦 yarn
  • 📦 pnpm
  • 📦 pnpx
  • 📦 rush
  • 📦 rushx
  • 📦 bun
  • 📦 bunx
  • 📦 pip
  • 📦 pip3
  • 📦 uv
  • 📦 poetry
  • 📦 uvx
  • 📦 pipx
  • 📦 pdm

Usage

Aikido Safe Chain demo

Installation

Installing the Aikido Safe Chain is easy with the installation script.

Unix/Linux/macOS

curl -fsSL https://github.com/AikidoSec/safe-chain/releases/download/1.5.23/install-safe-chain.sh -o /tmp/install-safe-chain.sh \
  && echo "b7eac1c7152f300b229b865193d16424ad52386d1898c75ffaf374fcb4eeed3d  /tmp/install-safe-chain.sh" | sha256sum -c - \
  && sh /tmp/install-safe-chain.sh \
  && rm /tmp/install-safe-chain.sh

Windows (PowerShell)

$installer = Join-Path $env:TEMP "install-safe-chain.ps1"
Invoke-WebRequest "https://github.com/AikidoSec/safe-chain/releases/download/1.5.23/install-safe-chain.ps1" -OutFile $installer -UseBasicParsing
$expectedHash = "7E1274C8D9110798383A995BBA622E986D5A01C53B8FB76CC6934509EB27CFF7"
if ((Get-FileHash $installer -Algorithm SHA256).Hash -ne $expectedHash) {
    Remove-Item $installer -ErrorAction SilentlyContinue
    throw "Checksum verification failed for install-safe-chain.ps1"
}
& $installer
Remove-Item $installer

The install commands above always reference a specific release. To install a different version, replace the version with your desired version number. All available versions are on the releases page.

Download integrity

The install scripts are served from a versioned release URL (releases/download/1.5.23/...). GitHub releases are immutable — once an artifact is published at a versioned URL it cannot be modified or replaced, so the file you download is guaranteed to be exactly what was released.

Verify the installation

  1. ❗Restart your terminal to start using the Aikido Safe Chain.

    • This step is crucial as it ensures that the shell aliases for npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, pip, pip3, poetry, uv, uvx, pipx and pdm are loaded correctly. If you do not restart your terminal, the aliases will not be available.
  2. Verify the installation by running the verification command:

    npm safe-chain-verify
    pnpm safe-chain-verify
    pip safe-chain-verify
    uv safe-chain-verify
    
    # Any other supported package manager: {packagemanager} safe-chain-verify
    
    • The output should display "OK: Safe-chain works!" confirming that Aikido Safe Chain is properly installed and running.
  3. (Optional) Test malware blocking by attempting to install a test package:

    For JavaScript/Node.js:

    npm install safe-chain-test
    

    For Python:

    pip3 install safe-chain-pi-test
    
    • The output should show that Aikido Safe Chain is blocking the installation of these test packages as they are flagged as malware.

When running npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, pip, pip3, uv, uvx, poetry, pipx and pdm commands, the Aikido Safe Chain will automatically check for malware in the packages you are trying to install. It also intercepts Python module invocations for pip when available (e.g., python -m pip install ..., python3 -m pip download ...). If any malware is detected, it will prompt you to exit the command.

You can check the installed version by running:

safe-chain --version

How it works

Malware Blocking

The Aikido Safe Chain works by running a lightweight proxy server that intercepts package downloads from the npm registry and PyPI. When you run npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, pip, pip3, uv, uvx, poetry, pipx or pdm commands, all package downloads are routed through this local proxy, which verifies packages in real-time against Aikido Intel - Open Sources Threat Intelligence. If malware is detected in any package (including deep dependencies), the proxy blocks the download before the malicious code reaches your machine.

Minimum package age

Safe Chain applies minimum package age checks to supported ecosystems.

Current enforcement differs by ecosystem:

  • npm-based package managers:
    • during normal package resolution, Safe Chain suppresses versions that are newer than the configured minimum age from the package metadata returned by the registry
    • for direct package download requests that bypass that metadata flow, Safe Chain can block the request itself using a cached list of newly released packages
  • Python package managers:
    • during package resolution, Safe Chain suppresses too-young files and releases from PyPI metadata responses
    • for direct package download requests that bypass that metadata flow, Safe Chain can block the request itself using a cached list of newly released packages

By default, the minimum package age is 48 hours. This provides an additional security layer during the critical period when newly published packages are most vulnerable to containing undetected threats. You can configure this threshold or bypass this protection entirely - see the Minimum Package Age Configuration section below.

For urgent CVE fixes, Aikido confirms the patch release is free of malware and Safe Chain exempts it from the minimum age check, so you're not left exposed to the vulnerability it fixes while waiting out the window.

Shell Integration

The Aikido Safe Chain integrates with your shell to provide a seamless experience when using npm, npx, yarn, pnpm, pnpx, rush, rushx, bun, bunx, and Python package managers (pip, uv, uvx, poetry, pipx, pdm). It sets up aliases for these commands so that they are wrapped by the Aikido Safe Chain commands, which manage the proxy server before executing the original commands. We currently support:

  • ✅ Bash
  • ✅ Zsh
  • ✅ Fish
  • ✅ PowerShell
  • ✅ PowerShell Core

More information about the shell integration can be found in the shell integration documentation.

Uninstallation

To uninstall the Aikido Safe Chain, use our one-line uninstaller:

Unix/Linux/macOS

curl -fsSL https://github.com/AikidoSec/safe-chain/releases/download/1.5.23/uninstall-safe-chain.sh | sh

Windows (PowerShell)

도구 다운로드