Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Customer Zero: Implementing Package Firewall at Endor Labs

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Devon Powley
Word Count
1,242
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Labs describes its internal rollout of the Package Firewall, released in May to prevent malicious or newly published software packages from being installed on developer endpoints and CI/CD systems through a 24-hour cooldown policy and malware-database checks. Initially skeptical about coverage, configuration tampering, and developer disruption, the Security team deployed the tool through endpoint management scripts and gained visibility into substantially more package activity than expected, including an average of roughly 135 daily attempts to install packages less than 24 hours old. The rollout found that many installations originated from coding-agent sessions, non-engineering employees, and automated updates from tools such as Claude Code, MCP servers, and VS Code extensions. Early blocking created developer friction because package managers often selected the newest version automatically and provided limited explanations for 403 errors, so Endor Labs introduced “curation,” which returns the latest compliant package version rather than blocking requests, and added Slack notifications explaining blocks. The company reports that these changes reduced interruptions while retaining protection, and firewall logs identified several near misses involving packages later found to be compromised, reinforcing the role of package controls against automated supply-chain threats.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.