Semgrep Malware Firewall is in private beta.
Overview
The Semgrep Malware Firewall prevents malicious packages from being installed on your machine. It sits in front of your package installs, checks each requested package against Semgrep’s continuously updated database of known malware, and blocks anything that matches.How it works
The firewall has the following parts:- A lightweight client proxy that runs on every machine.
- You set it up once with
mfw install. It sets the standard proxy environment variablesHTTP_PROXYandHTTPS_PROXYso package managers respect it automatically—no per-tool configuration is needed. For example, you don’t need to set uptool.uv.indexmanually foruv. - It watches traffic to known package registry URLs such as
registry.npmjs.org, identifies package-download requests specifically—including tarballs, wheels, and similar artifacts—and gates those artifact requests on a response from the Semgrep backend before the download completes. - All other traffic is proxied through transparently.
- You set it up once with
- The Semgrep-operated malware firewall backend, which receives requests from the local proxy containing an ecosystem, package name, and version, and replies with a verdict.
- The malware database that is continuously updated from a variety of threat feeds and maintained by Semgrep’s security research team.
- On install, the firewall runs
mfw loginto sign you in. Each verdict request is then authenticated with a short-lived bearer token. - When you run a normal package install, the local proxy intercepts every package the installer tries to fetch.
- The proxy asks the Semgrep backend whether the specific version of that package is malicious.
- The backend matches the version to the malware database and returns a verdict.
- If the package is safe, the install proceeds normally. If it matches known malware, the proxy blocks the download and reports why.
Advisory and database sync objectives
- For active, high-severity supply chain incidents, Semgrep’s security research team works to issue and deploy an advisory as soon as a threat is identified rather than waiting for it to be published to sources like the Open Source Vulnerabilities (OSV) database.
- For all other findings, the malware database syncs from OSV every 2 hours.
Cooldowns
The firewall doesn’t currently support configuring a cooldown period before a newly published package version can be installed. You can configure cooldowns at the package-manager level. See cooldowns.dev for a guide across ecosystems.Reporting
Semgrep AppSec Platform shows basic firewall reporting, including scanned and blocked dependencies, in the Malware firewall section of the Dashboard.Prerequisites
- You must have an active Semgrep account
- You must have Semgrep Guardian enabled
- You must have access to a macOS or Linux terminal or shell
Supported languages
The firewall works with projects written in Go, JavaScript, Python, and Rust.Install and verify
You can install the firewall with the Semgrep Guardian skill or manually with the install script. If you already use Semgrep Guardian, the/install-mfw skill is the quickest path — it installs and configures everything for you.
- With Semgrep Guardian
- Manual install
Semgrep Guardian ships with an
/install-mfw skill that installs and sets up the firewall for you.1
In your AI coding agent with the Semgrep Guardian plugin installed (such as Claude Code), run:
2
Follow the prompts. The skill downloads the
mfw client, adds a local certificate authority to your trust store, sets up shell integration and a background daemon, and walks you through signing in.3
Restart your Terminal / shell so the proxy environment variables take effect.
Test the firewall
Use a known-safe demo package to confirm that the firewall blocks malicious installs without touching real malware.1
Open or create a test directory and initialize a project:
2
Attempt to install the demo malware package:
3
Expected result: the install is blocked. The firewall should intercept and reject the package.
4
To test with a second package manager, repeat with pip:
mfw doctor output, and see Troubleshoot mfw doctor failures.
Determine whether a specific dependency version is malicious
Themfw api command can be used to determine if a specific version of a package is malicious:
Uninstall the firewall
To remove the firewall and its proxy configuration from a machine:HTTP_PROXY and HTTPS_PROXY environment variables that mfw install configured and removes the local proxy process. Restart your terminal or shell afterward to confirm that the variables are cleared.
To verify removal:
Semgrep mfw is protecting this machine ✅.