# Install lavamoat with npm

lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks". Version 11.1.4 via npm; verified 2026-06-25.

## Install

```sh
sudo av install npm:lavamoat
```

Additional install commands:

### Portable and language managers

- npm (100%):

```sh
npm install -g lavamoat
```

  Evidence: local npm package metadata

## Package facts

- **Package key:** npm:lavamoat
- **Package manager:** npm
- **Package manager page:** <https://www.npmjs.com/package/lavamoat>
- **Version:** 11.1.4
- **Source summary:** lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks".
- **Homepage:** <https://github.com/LavaMoat/lavamoat#readme>
- **Repository:** <https://github.com/LavaMoat/lavamoat>
- **Upstream docs:** <https://github.com/LavaMoat/lavamoat#readme>
- **License:** MIT
- **Source archive:** <https://registry.npmjs.org/lavamoat/-/lavamoat-11.1.4.tgz>
- **Issue tracker:** <https://github.com/LavaMoat/lavamoat/issues>
- **Published:** 2026-06-25T12:03:12.741Z
- **Last updated:** 2026-06-25T12:03:12.741Z
- **Generated:** 2026-08-04T22:13:35+00:00

## Executables

- lavamoat (cli)
- lavamoat-run-command (cli)
- lavamoat (alias)

## Dependencies

- @babel/code-frame
- @babel/highlight
- @lavamoat/aa
- bindings
- htmlescape
- lavamoat-core
- lavamoat-tofu
- node-gyp-build
- resolve
- yargs

## Install behavior

- Post-install hook: not defined
- Bottle: not available

## Freshness

- Page generated: 2026-08-04
- Package-manager version: 11.1.4
- Package-manager updated: 2026-06-25
- Local data: ok
- Upstream repository: https://github.com/LavaMoat/lavamoat
- info: No cached GitHub release or tag data was available.

## Security Notes

No matching local secret-handling manifest was found for lavamoat. Package metadata is still published here so future coverage has a stable package URL.


## Source Database Details

- **Source Database:** npm registry
- **Dist Tags:** Latest: 11.1.4
- **Version Count:** 100
- **Maintainers:** kumavis, naugtur, boneskull
- **Author:** kumavis
- **Publisher:** GitHub Actions
- **Engines:** Node: ^20.19.0 || ^22.5.1 || ^24.0.0
- **Integrity:** sha512-YbdH4eJkC7clqdU2xd3byorMyMpU5OigtU5kf9Gjcg0O+unLeIZ6Ct6sM/k19rBbEwo2/k/JtfpWXqaaxmTI4A==
- **Shasum:** 53d56ddac60b127e210820972bef0027ec1cfe59
- **Unpacked Size:** 84,053
- **File Count:** 0
- **Created At:** 2020-03-27T04:53:19.858Z
- **Latest Published At:** 2026-06-25T12:03:12.741Z
- **Modified At:** 2026-06-25T12:03:13.056Z


## Related links

- [Security and crypto packages](https://pkg.so/security-crypto-tools/) - Matched curated package taxonomy and local package facts.
- [lavamoat-core](https://pkg.so/npm/lavamoat-core/) - Security-sensitive metadata or terminology overlaps. Shared terms: babel, chain, cli, core, dependencies.
- [lockfile-lint](https://pkg.so/npm/lockfile-lint/) - Security-sensitive metadata or terminology overlaps. Shared terms: chain, cli, security, supply, supply-chain-security.
- [vm2](https://pkg.so/npm/vm2/) - Both packages touch the same language runtime or ecosystem. Shared terms: cli, code, is, modules, node.

## Sources

- pkg.so package database
- package-page enrichment
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- cross-ecosystem install command graph
