Chainguard Libraries now available on AWS Security Hub Extended
Today, we're introducing Chainguard Libraries in the AWS Security Hub Extended Supply Chain category, helping all businesses that build on Amazon Web Services (AWS) stay secure from the next supply chain attack.
The Security Hub Extended plan includes a curated set of best-of-breed partner tools, centralized in one security operations experience. The Supply Chain category covers the open source dependencies engineers pull in before anything runs, now featuring a secure catalog of Python, Java, and JavaScript packages that replaces npm, PyPI, and Maven Central.
Why the software supply chain needed a category of its own
This is the year the software supply chain became a daily target. In March and April alone, attackers compromised Trivy, LiteLLM, Telnyx, Axios, Elementary Data, and Intercom-Client one after another, and the Mini Shai-Hulud worm recently hit @redhat-cloud-services npm packages with millions of weekly downloads. These attacks aren't outliers: In Black Duck's 2025 survey, 65 percent of organizations reported experiencing a software supply chain attack in the past year, and they're growing more frequent and more sophisticated. Security teams are searching for answers, vendors are racing to provide them, and AWS's designation of the software supply chain as a separate category is a clear signal that this is now a first-class security problem.
The issue is that most tools on the market remain reactive, and these attacks move too quickly for a reactive approach to work. More than 98 percent of malware ships as a pre-built package with no matching source code (CITE). A malicious version goes live, gets pulled into builds around the world within hours, and the damage is done well before a malware scanner flags. AI coding is accelerating that cycle on both sides: engineers and agents pull dependencies faster than any review can keep up with, while attackers automate more convincing malware into the packages you rely on.
What the supply chain needs is to be secure by default. That means pulling in dependencies that are built clean before they enter your environment, so malware has no way in.
What Chainguard Libraries brings
Chainguard Libraries is a malware-free catalog of language dependencies that replaces your team's reliance on public registries. Instead of pulling packages straight from those registries, your engineers and AI agents pull from a registry where every package has already passed through multiple layers of protection.
Chainguard rebuilds packages in the Chainguard Factory, an isolated SLSA L3 build environment that stops malware before it can exist. More than 98 percent of malware ships as a pre-built package with no matching source code. Chainguard rebuilds only from verified source and adds protections like source code scanning, maintainer behavior monitoring, and cooldown periods that help catch suspicious or malicious changes before a package is ever developed.
A few examples:
Axios: Two malicious axios releases hit a package with 300M+ monthly downloads. The attack introduced a hidden malicious dependency, but Chainguard never built that dependency because it used install-time scripts, so the payload never reached Chainguard customers.
LiteLLM: Attackers published malicious LiteLLM versions to PyPI for a package with 97M+ monthly downloads, while the upstream GitHub source stayed clean. Because the malicious releases had no matching upstream source, Chainguard never built or published them.
Telnyx: Attackers pushed malicious telnyx versions to PyPI for a package with ~790K monthly downloads. Those releases had no corresponding commits on GitHub, so Chainguard never built or served them
Chainguard Libraries are drop-in replacements, with no changes to engineering workflows. Every package ships with signed provenance and SBOMs, providing auditors with verifiable evidence for frameworks such as FedRAMP, CRA, and DORA. Additionally, for Python, Chainguard backports fixes for critical and high-severity CVEs in popular libraries like Django and Flask, so teams stay secure while planning their next upgrade. When the next attack hits, your engineers stay on roadmap work instead of asking, "Are we impacted?”
What you get with the Extended Plan
You subscribe to Chainguard Libraries directly in the Security Hub console, under Management → Extended plan → Supply Chain. Through the Extended plan, you get:
One bill, no new contract. Chainguard Libraries is pay-as-you-go on your existing AWS bill with no long-term commitment
Unified findings: Chainguard findings are normalized to the Open Cybersecurity Schema Framework (OCSF) and appear alongside your AWS and partner findings in the same Security Hub view
Unified support: AWS Enterprise Support customers get Level 1 support directly from AWS.
Prevention is the only solution
Software supply chain attacks won't slow down, and the past year proved that catching them after they ship is too late. That's the problem AWS built a category around, and it's the one Chainguard Libraries solves. Chainguard’s malware-free catalog delivers open source you can trust by default.
Get in touch with our team to learn more.
Share this article
Verwandte Artikel
- Produkt
Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java
Matt Stead, Product Marketing Manager
- Produkt
Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA
Ross Gordon, Staff Product Marketing Manager
- Produkt
Everything we announced during AI Readiness Innovation Week
Patrick Donahue, SVP, Product
- Produkt
Chainguard plug-in now available on Cursor Marketplace
Matt Stead, Product Marketing Manager
- Produkt
Securing the AI coding ecosystem: Chainguard and the AI tools developers use
Matt Stead, Product Marketing Manager
- Produkt
Secure your pipelines with Chainguard Actions, now available in Open Beta
Elsie Phillips, Staff Product Marketing Manager