Forem

npm

Node Package Manager

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns

The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns

Comments
4 min read
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
Cover image for I built Material Symbols SVG, an icon library for using Material Symbols as SVG components

I built Material Symbols SVG, an icon library for using Material Symbols as SVG components

Comments
5 min read
Why Your AI Coding Agent Keeps Recommending Dead Packages

Why Your AI Coding Agent Keeps Recommending Dead Packages

1
Comments
2 min read
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution

Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution

Comments
7 min read
Supply Chain Security measures
Cover image for Supply Chain Security measures

Supply Chain Security measures

Comments
1 min read
Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm
Cover image for Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm

Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm

Comments
5 min read
The Axios/npm Incident & Why AI Won’t Replace Devs

The Axios/npm Incident & Why AI Won’t Replace Devs

Comments
1 min read
I built an npm malware scanner and found 21 malicious packages in 24 hours

I built an npm malware scanner and found 21 malicious packages in 24 hours

Comments 1
1 min read
How the axios@1.14.1 supply chain attack worked (and how to protect yourself)

How the axios@1.14.1 supply chain attack worked (and how to protect yourself)

Comments
4 min read
What the Axios npm Compromise Means for MCP Server Maintainers

What the Axios npm Compromise Means for MCP Server Maintainers

Comments
4 min read
How to Finally (and Iteratively) Kill Every Last 'npm audit'

How to Finally (and Iteratively) Kill Every Last 'npm audit'

Comments
3 min read
.me

.me

4
Comments
6 min read
The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.

The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.

Comments
2 min read
How I Would Have Stopped the March 2026 Axios Supply Chain Attack (Free Tool Inside)

How I Would Have Stopped the March 2026 Axios Supply Chain Attack (Free Tool Inside)

Comments
2 min read
I Built a CLI That Shows the Real Cost of Your node_modules (Size + Security + Age)

I Built a CLI That Shows the Real Cost of Your node_modules (Size + Security + Age)

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.