Block Malicious Packages Across Your Organization with Supply Chain Firewall and Code Security
Datadog, Thursday, October 1st, 2026
Datadog Code Security now manages its open-source Supply Chain Firewall centrally, with allowlists, blocklists and a CI GitHub action.
Citing npm campaigns such as Shai-Hulud 2.0, Datadog notes teams need checks before packages are installed, not just after.
Its open-source Supply Chain Firewall intercepts npm, pip and poetry commands to block known-malicious packages.
Datadog Code Security now supports it as an organization-wide control with central allowlist and blocklist management and retroactive detection of installed packages later found to be malicious, and a new GitHub action extends protection to CI workflows.