Chainguard LIBRARIES FOR JAVASCRIPT
Stay protected from the next Shai-Hulud

Chainguard Libraries for JavaScript are drop-in replacements for your npm packages, built from source in a SLSA L3-compliant environment so the next malware incident isn't your problem.

image
4.7 Stars on G2

The world’s leading companies trust Chainguard

  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • Logo of Chainguard customer GitLab.
  • customer logo
  • Snap logo.
  • customer logo
  • customer logo
  • customer logo
  • customer logo
  • Logo of Chainguard customer SolarWinds
  • customer logo
  • Logo of Chainguard customer Siemens
  • customer logo
  • customer logo
  • VP Bank logo.
  • customer logo
  • customer logo
  • customer logo
  • Logo of Chainguard customer Ironclad
  • Logo of Chainguard customer Wistia.
  • customer logo
  • customer logo
  • logo of Chainguard customer logicmonitor
  • Logo of Chainguard customer Fortinet

System scale

Access thousands of JavaScript packages that replace what you get from npm — with more being added every week

Proactive malware prevention

Stay protected from malicious attacks often inserted during the build and distribution stages of package creation.

Verification by default

Every library is built in a secure, SLSA L3 build system with full provenance and signed SBOMs to prove supply chain integrity.

System scale

Access thousands of JavaScript packages that replace what you get from npm, with more being added every week.

Expertise and experience

The leading open source minds driving the industry forward, delivering new innovations for developers.

Malwhere? Not here.

Since 99.7% of npm malware has no verifiable source code, building from source means you would have been immune from these incidents.

chalk, debug, and more — Sep. 2025

Phished maintainer credentials were used to publish malicious versions of packages with 2.6B weekly downloads. Chainguard would not have built them as no verifiable source code existed.

Sha1-Hulud — Nov. 2025, and Shai-Hulud — Sep. 2025

Two worms deployed via stolen bot credentials exposed thousands of developer secrets and led to Trust Wallet losing $8.5M in assets. Chainguard Libraries for JavaScript doesn't build libraries that use pre-install scripts.

Solana Web3.js — Dec. 2024

A compromised maintainer account published a backdoor that drained $160K in crypto assets. Chainguard would not have built it since there was no verifiable source code.

is — Sep. 2025

Phished maintainer credentials backdoored a package with 2.8M weekly downloads before npm removed it hours later. Since only credentials were compromised and the malware did not have source code, Chainguard wouldn’t have built it.

Multiple layers of security protect your team from the next attack

Covers all of your dependencies

Covers all of your dependencies

Access the web development stack that you need, such as TypeScript, Node.js, and React, along with every other project you required to build your application.

Signed, sealed, and dependable

Signed, sealed, and dependable

Every Chainguard-built version comes with signed provenance and SBOMs, giving you indisputable proof that your dependencies came from the SLSA L3-compliant Chainguard Factory, not a vulnerable maintainer’s machine.

Works with your existing tooling

Works with your existing tooling

Chainguard Libraries works with your existing artifact managers and workflows. Each package has the same functionality as to what you’ll find on npm, so there are no breaking changes. Your engineers won’t notice a difference.

CG System promptExecute command

$ chainguard learn --more

contact us

Frequently Asked Questions