# Protection from Recent npm Malware Attacks

**URL:** <https://community.sonatype.com/t/protection-from-recent-npm-malware-attacks/15579>\
**Category:** Community Announcements\
**Created:** [September 22, 2025, 5:22pm UTC](https://community.sonatype.com/t/protection-from-recent-npm-malware-attacks/15579 "2025-09-22T17:22:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jzora](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jzora/32/4197_2.png) [@jzora](https://community.sonatype.com/u/jzora)\
**Post date:** [September 22, 2025, 5:22pm UTC](https://community.sonatype.com/t/protection-from-recent-npm-malware-attacks/15579/1 "2025-09-22T17:22:09Z")

</div>

Over the last two weeks, npm has seen a number of novel malware attacks. If you’re a Repository Firewall customer, **you can protect your software supply chain from these threats.** The following instructions assume that you own Repository Firewall but aren’t currently using Repository Firewall to block incoming threats.

**For more instructions on finding, removing, and protecting yourself this new malware, see our [new documentation page about the issue.](https://help.sonatype.com/en/understanding-the-shai-hulud-npm-worm-attack.html)**

## Prerequisites

Ensure Sonatype IQ Server is installed and licensed for Repository Firewall.  
 Connect Nexus Repository Manager to IQ Server.  
 Confirm the Firewall feature is enabled on the target artifact manager.

## Enable Firewall Audit and Quarantine in Nexus Repository Manager

In Nexus Repository Manager, go to Settings → System → Capabilities.  
 Add a new capability: Firewall: Audit and Quarantine.  
 Select the target proxy repository.  
 Check Enable Quarantine for Repository and save.

- Note: Quarantine must be enabled to block critical threats. Disabling quarantine releases all previously quarantined components, and they will not be re-quarantined unless newly requested.

## Verify Required Policies in IQ Server

Verify the _Security-Malicious_ policy. Make sure the details match the below exactly.

- Name: Security-Malicious
- Threat Level: 10 (Critical)
- Inheritance: All Applications and Repositories
- Constraint: “Security Vulnerability Category is Malicious Code”
- Actions: Set to Fail at the Proxy stage and all other states.
- Notifications: As desired (recommend including Proxy stage)

Reference: [Security Policies](https://help.sonatype.com/en/security-policies.html)

Verify the _Integrity-Rating_ policy.

- Purpose: Protects against releases flagged by Sonatype’s ML/AI or under review.
- Configuration:
  - Name: Integrity-Rating
  - Threat Level: 9 (Critical)
  - Inheritance: All Applications and Repositories
  - Constraints:
    - “Pending integrity rating” → Integrity Rating is Pending
    - “Suspicious integrity rating” → Integrity Rating is Suspicious

  - Actions: Set to Fail at the Proxy stage
  - Notifications: As desired (recommend including Proxy stage)

Reference: [Release Integrity](https://help.sonatype.com/en/release-integrity.html)

## Validate Policy Application

In Nexus Repository, verify that each npm proxy repository has the “Firewall: Audit and Quarantine” capability enabled with the “Quarantine” option checked.

**OR**

In Repository Firewall, go to the “Repository Managers” view, sort by Format, and verify that each npm proxy repository has “Audit, Quarantine” in the Enablement column.

## Understand Scope: New Versus Existing Components

Repository Firewall only quarantines newly requested components. Components already in proxy repositories will be audited, but not quarantined. Use the [Automatic Malware Management task](https://help.sonatype.com/en/malware-risk.html#automatic-malware-management-task) to remove malware that’s already in your proxy repositories.

## Best Practices

Enable [Policy Compliant Component Selection](https://help.sonatype.com/en/policy-compliant-component-selection.html) and [Automatic Quarantine Release](https://help.sonatype.com/en/automatic-quarantine-release.html) to minimize development friction.  
 **Notify development teams about the change in enforcement,** and make a plan for managing quarantined components and automatic releases.  
 Schedule a meeting with your Customer Success rep to check your configuration for maximum effectiveness.

---

<div class="post-metadata">

**Author:** ![Kiran\_Kumar](https://avatars.discourse-cdn.com/v4/letter/k/f475e1/32.png) [@Kiran\_Kumar](https://community.sonatype.com/u/Kiran_Kumar)\
**Post date:** [September 23, 2025, 5:47am UTC](https://community.sonatype.com/t/protection-from-recent-npm-malware-attacks/15579/2 "2025-09-23T05:47:13Z")

</div>

Hi Jonathan,  
Can you please provide more details on OSS nexus to protect npm malware ?
