Forem

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
smart-seo-lite — a lightweight npm package

smart-seo-lite — a lightweight npm package

1
Comments
1 min read
AI is writing our code... but who is auditing the AI?
Cover image for AI is writing our code... but who is auditing the AI?

AI is writing our code... but who is auditing the AI?

Comments
3 min read
Two Types of npm Supply Chain Attack: What Catches Each

Two Types of npm Supply Chain Attack: What Catches Each

Comments
5 min read
How I responded to a Supply Chain attack before it hit my project

How I responded to a Supply Chain attack before it hit my project

3
Comments 3
3 min read
The axios supply chain attack bypassed every CVE scanner. Behavioral scoring saw it coming.

The axios supply chain attack bypassed every CVE scanner. Behavioral scoring saw it coming.

Comments
3 min read
Lazy SRE's guide to secure systems, part 1: the dependencies you didn't read
Cover image for Lazy SRE's guide to secure systems, part 1: the dependencies you didn't read

Lazy SRE's guide to secure systems, part 1: the dependencies you didn't read

Comments
7 min read
572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

1
Comments
3 min read
node_modules is Why Your Mac is Full: Find and Delete All of Them
Cover image for node_modules is Why Your Mac is Full: Find and Delete All of Them

node_modules is Why Your Mac is Full: Find and Delete All of Them

6
Comments
8 min read
Continuous monitoring caught a credential leak in a published MCP package. Six republishes later, it is still there.

Continuous monitoring caught a credential leak in a published MCP package. Six republishes later, it is still there.

Comments
7 min read
Your .claude/ Directory Is Now a Supply Chain Target

Your .claude/ Directory Is Now a Supply Chain Target

Comments
5 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

Comments
3 min read
Why Your LLM Agent Forgot What It Did 5 Steps Ago
Cover image for Why Your LLM Agent Forgot What It Did 5 Steps Ago

Why Your LLM Agent Forgot What It Did 5 Steps Ago

1
Comments
4 min read
Supply Chain Attacks Targeting Bitwarden CLI and How to Defend
Cover image for Supply Chain Attacks Targeting Bitwarden CLI and How to Defend

Supply Chain Attacks Targeting Bitwarden CLI and How to Defend

Comments
5 min read
No, the AI didn't compromise your npm packages. You did.
Cover image for No, the AI didn't compromise your npm packages. You did.

No, the AI didn't compromise your npm packages. You did.

3
Comments 1
13 min read
TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm

TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm

6
Comments 2
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.