Protection from Recent npm Malware Attacks - Community Announcements - Sonatype Community

Protection from Recent npm Malware Attacks

post by jzora on Sep 22, 2025

Over the last two weeks, npm has seen a number of novel malware attacks. If you’re a Repository Firewall customer, you can protect your software supply chain from these threats. The following instructions assume that you own Repository Firewall but aren’t currently using Repository Firewall to block incoming threats.

For more instructions on finding, removing, and protecting yourself from this new malware, see our new documentation page about the issue.

Prerequisites

Enable Firewall Audit and Quarantine in Nexus Repository Manager

In Nexus Repository Manager, go to Settings → System → Capabilities.

  1. Add a new capability: Firewall: Audit and Quarantine.
  2. Select the target proxy repository.
  3. Check Enable Quarantine for Repository and save.

Note: Quarantine must be enabled to block critical threats. Disabling quarantine releases all previously quarantined components, and they will not be re-quarantined unless newly requested.

Verify Required Policies in IQ Server

Verify the Security-Malicious policy. Make sure the details match the below exactly.

Verify the Integrity-Rating policy.

Validate Policy Application

In Nexus Repository, verify that each npm proxy repository has the “Firewall: Audit and Quarantine” capability enabled with the “Quarantine” option checked.

OR
In Repository Firewall, go to the “Repository Managers” view, sort by Format, and verify that each npm proxy repository has “Audit, Quarantine” in the Enablement column.

Understand Scope: New Versus Existing Components

Repository Firewall only quarantines newly requested components. Components already in proxy repositories will be audited, but not quarantined. Use the Automatic Malware Management task to remove malware that’s already in your proxy repositories.

Best Practices