safe-chain: Aikido Safe Chain and the Art of the Benevolent MITM

How a local proxy intercepts your package manager to manipulate registry metadata and block zero-day supply chain attacks before they hit your disk.

7 min read • View on GitHub • More from AikidoSec

A heavily armored tollbooth on a dirt road where a toll operator redacts a single line of text from a sealed letter with a thick black marker before resealing it. This metaphorically represents Safe Chain's local MITM JSON manipulation.
Safe Chain intercepts secure traffic to rewrite package metadata on the fly.
Key Takeaways

The Localhost Heist

When a developer types npm install, the expectation is a direct, secure line to registry.npmjs.org. Aikido Safe Chain breaks that assumption entirely. It executes a Man-in-the-Middle (MITM) attack on your own local environment.

Instead of talking to the public registry, your package manager communicates with a local Node.js server spawned on a random port. This proxy intercepts HTTPS traffic using the CONNECT method. Because it needs to inspect the payload, it uses node-forge to generate fake SSL certificates on the fly, decrypting, inspecting, and re-encrypting the data stream.

The local MITM proxy architecture.

The 24-Hour Danger Zone

This aggressive interception is necessary because of the fundamental latency in malware detection. Public registries do scan for malicious code, but community vetting takes time. The first 24 to 48 hours of a package's life are radioactive.

If a developer pulls a compromised package during this initial window, traditional static analysis tools and lockfile scanners fail. They are reactive, alerting you only after the malware has executed its post-install scripts on your machine.

A close-up of a heavy mechanical countdown timer bolted to the latch of a wooden shipping crate, physically preventing it from being opened. This illustrates the 24-hour minimum age quarantine.
The 24-hour minimum age quarantine locks down fresh, unvetted releases.

Safe Chain now enforces a minimum package age, holding any version published in the last 24 hours so it can be analysed properly before install. Fresh releases are the easiest place for attackers to hide, so this window gives security tools enough time to analyse them. If a version is too new and not yet verified, Safe Chain automatically falls back to an older clean version. It does not break builds. Safe Chain is free, open source and runs locally.

Trusha Sharma, Writer for Aikido Blog · SafeChain Now Enforces a Minimum 24-Hour Package Age...

Lying to the Resolution Engine

The most elegant feature of Safe Chain is how it handles these quarantined packages. A naive firewall would simply block the connection, returning a "Connection Refused" error that immediately crashes the CI/CD pipeline.

Safe Chain takes a different approach: it alters reality. In modifyNpmInfo.js, the proxy intercepts the JSON metadata returned by the registry. It parses the payload, identifies versions younger than the quarantine threshold, and silently deletes them from the response.

// Intercepted Registry Response (Before)
{
  "name": "example-package",
  "dist-tags": {
    "latest": "2.1.0"
  },
  "versions": {
    "2.0.9": { ... },
    "2.1.0": { ... } // Published 2 hours ago
  }
}

// Modified Response (After Safe Chain)
{
  "name": "example-package",
  "dist-tags": {
    "latest": "2.0.9"
  },
  "versions": {
    "2.0.9": { ... }
  }
}

The package manager receives this modified JSON and assumes the older, safe version is the latest release. It installs the vetted code seamlessly, keeping the build green while avoiding the zero-day threat.

Polyglot Protection

Despite its Node.js roots, Safe Chain is designed to protect polyglot environments. It achieves this through intelligent shell integration, modifying .bashrc or .zshrc to alias common package manager commands.

When a developer runs a command, a factory pattern in currentPackageManager.js detects the context—whether it's npm, yarn, bun, or pip. It then routes the request to the appropriate adapter, applying the correct command-argument scanning logic without requiring the developer to change their workflow.

The Post-Lockfile Reality

The industry standard for supply chain security has long been reactive lockfile scanning. Tools analyze your package-lock.json to tell you that you downloaded malware yesterday. Safe Chain shifts this paradigm.

A split composition: on the left, a detective examines a muddy footprint in a robbed house; on the right, a stern guard checks ID at a fortified gate. This contrasts post-install scanning with pre-install prevention.
Reactive post-install scanning vs. proactive pre-install interception.
FeatureTraditional SCAAikido Safe Chain
Intervention PointPost-installPre-install
MechanismStatic file analysisNetwork MITM
Zero-Day DefenseRelies on CVE DBMinimum Age Quarantine
Build ImpactFails CI pipelineSilent downgrade

By operating at the network layer, Safe Chain ensures that malicious code never executes its install scripts on your machine. It is a proactive defense mechanism that treats the local development environment—and the CI/CD runner—as the critical perimeter.

We just launched Aikido Safe-Chain, a secure wrapper for npm, npx, and yarn that sits in your current workflow and checks every package for malware before install. It protects you against dependency confusion, backdoors, typosquats, and other supply chain threats in real-time without altering your workflow.

Mackenzie Jackson, Writer for Aikido Blog · Introducing Safe Chain