---
title: "dnpm Configurator"
description: "Generate a hardened Docker-based npm wrapper that sandboxes every install, build, and dev command. Blocks postinstall attacks, drops all capabilities, runs as non-root, builds with zero network access, and includes a 6-point security scanner."
url: https://findutils.com/developers/dnpm-configurator/
category: developers
---

# dnpm Configurator

Generate a hardened Docker-based npm wrapper that sandboxes every install, build, and dev command. Blocks postinstall attacks, drops all capabilities, runs as non-root, builds with zero network access, and includes a 6-point security scanner.

**Use this tool:** [dnpm Configurator](https://findutils.com/developers/dnpm-configurator/)

## Programmatic access

- REST id `dnpm-configurator`: POST https://api.findutils.com/api/tools/dnpm-configurator/execute (reference: https://findutils.com/api/dnpm-configurator/)
- MCP tool `dnpm_configurator` on https://mcp.findutils.com (reference: https://findutils.com/mcp/dnpm-configurator/)

## Why Use dnpm?

The npm ecosystem faces a growing supply chain attack surface. In April 2026, compromised versions of axios (1.14.1 and 0.30.4) were published with a remote access trojan hidden in a postinstall script. Running npm install on bare metal means these scripts execute with full access to your filesystem, SSH keys, and credentials. dnpm wraps every npm operation inside a hardened Docker container. Your project is mounted read-only, all Linux capabilities are dropped, and postinstall scripts are disabled by default. When you do need lifecycle scripts (like native module compilation), they run in a separate phase with zero network access — so even if malicious code executes, it cannot phone home or exfiltrate data. The dnpm check command runs a 6-point security scan after every setup: lockfile integrity, npm audit, signature verification, Socket.dev behavioral analysis, deprecated package detection, and container image CVE scanning via Trivy. Reports are saved to.dnpm/reports/ with timestamped files and a latest.txt for easy review. dnpm setup also auto-injects usage instructions into your project's CLAUDE.md, ensuring AI coding assistants use the sandboxed wrapper instead of bare npm. The injection is idempotent and safe to run repeatedly. Unlike bun's approach of simply skipping postinstall scripts, dnpm provides defense in depth: seccomp syscall filtering, noexec tmp, non-root user, resource limits, and lockfile integrity checks. It works with any Node.js project and requires only Docker.

## Frequently Asked Questions

### Does dnpm replace npm?

No. Dnpm wraps npm inside a secure Docker container. Every npm command you know still works — dnpm just adds isolation and security layers around it.

### Will my npm scripts still work?

Yes. Scripts defined in package.json (dev, build, test, etc.) work normally. Lifecycle scripts like postinstall are disabled by default but run in the offline rebuild phase when you use dnpm setup or dnpm ci.

### Does it work with yarn or pnpm?

The generated setup is npm-focused, but you can modify the Dockerfile and compose file to use yarn or pnpm instead. The security model (read-only mount, seccomp, capability dropping) works identically.

### Why not just use bun?

Bun skips postinstall scripts by default, which helps. But the malicious code still gets downloaded to node_modules, and bun doesn't provide filesystem isolation, capability dropping, seccomp filtering, or network isolation. dnpm provides defense in depth.

### Is there a performance impact?

Docker adds minimal overhead for dev servers and builds. The initial image build takes ~30 seconds. After that, dnpm run dev starts as fast as native npm. File watching works via polling (configurable) which uses slightly more CPU on macOS.

### What does dnpm check scan for?

dnpm check runs a 6-point security scan: lockfile integrity (detects registry poisoning), npm audit (known CVEs), signature verification (tamper detection), Socket.dev behavioral analysis (suspicious runtime behaviors), deprecated package detection, and container image CVE scanning via Trivy. Reports are saved to.dnpm/reports/ with timestamped files and a latest.txt symlink.

### Does dnpm modify my CLAUDE.md?

Yes, dnpm setup automatically prepends dnpm usage instructions to your project's CLAUDE.md so AI coding assistants use./dnpm instead of bare npm. If no CLAUDE.md exists, one is created. The injection is idempotent — running setup multiple times will not duplicate the instructions.

### Does the dnpm Configurator require a signup?

No. It is available with no signup and no usage limits. The Dockerfile, compose file, and CLAUDE.md snippet are generated in your browser.
