Forem

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Attempt to stop npm postinstall scripts from stealing your secrets

Attempt to stop npm postinstall scripts from stealing your secrets

1
Comments
4 min read
npm Is on Fire: Why the Architecture Is the Product

npm Is on Fire: Why the Architecture Is the Product

Comments
10 min read
attw script in CopilotKit codebase.

attw script in CopilotKit codebase.

Comments
3 min read
42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now
Cover image for 42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

Comments
10 min read
The TanStack npm Attack Shows Why pnpm 11 Matters
Cover image for The TanStack npm Attack Shows Why pnpm 11 Matters

The TanStack npm Attack Shows Why pnpm 11 Matters

2
Comments
3 min read
LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages
Cover image for LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

Comments
3 min read
I got tired of calculating commercial lease billing by hand, so I built a tool

I got tired of calculating commercial lease billing by hand, so I built a tool

Comments
2 min read
The Worm in the Registry
Cover image for The Worm in the Registry

The Worm in the Registry

2
Comments
10 min read
Sonner vs. robot-toast: When "Invisible" UI Isn't Enough

Sonner vs. robot-toast: When "Invisible" UI Isn't Enough

1
Comments
1 min read
TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm

TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm

6
Comments 1
8 min read
Automate Social Media Image Generation with n8n + RenderPix
Cover image for Automate Social Media Image Generation with n8n + RenderPix

Automate Social Media Image Generation with n8n + RenderPix

Comments
6 min read
I Built My Own Config Format for Node.js That Separates Server and Client Secrets

I Built My Own Config Format for Node.js That Separates Server and Client Secrets

1
Comments 2
5 min read
Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks
Cover image for Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks

Comments
9 min read
Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen
Cover image for Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen

Comments
10 min read
Stop Shipping Broken Env Configs — I Built a Fix

Stop Shipping Broken Env Configs — I Built a Fix

Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.