Hackernews posts about NPM
NPM is a package manager for JavaScript that allows developers to easily install and manage dependencies in their projects, serving as a central registry for millions of open-source packages.
Related:
Ledger
- NPM flooded with malicious packages downloaded more than 86k times (arstechnica.com)
- How Cloudflare's client-side security made the NPM supply chain attack non-event (blog.cloudflare.com)
- Crims Poison 150K+ NPM Packages with Token-Farming Malware (www.theregister.com)
- NPM flooded with malicious packages downloaded more than 86,000 times (arstechnica.com)
- Show HN: [npm] Recreation of YouTube's "ambient glow" effect (www.npmjs.com)
- Undelete NPM Packages (www.npmjs.com)
- WASM based 3D viewer available in npmjs (www.npmjs.com)
- NPM install Vite is broken (github.com)
- StackTCO – find the right NPM packages for your framework (www.stacktco.com)
- Malicious packages in NPM evade dependency detection through invisible URL links (www.csoonline.com)
- Analyzing a NPM Spam Campaign: The Great Indonesian Tea Theft (www.endorlabs.com)
- Next.js 16's Turbopack breaks NPM link (www.steveharrison.dev)
- Show HN: Secure Extensions Marketplace for Chrome,Edge,Firefox,VSCode,NPM (browsertotal.com)
- Fake packages flood NPM registry in major attack – here's what we know (www.techradar.com)
- NPM-GitNameCheck (firexcore.com)
- Building a more secure NPM ecosystem with Mend Renovate (www.mend.io)
- Show HN: Interactive timelines from Markdown – Chronos Timeline (clairefro.github.io)
- Show HN: spoilerjs – Reddit-style spoilers with particle animations (spoilerjs.sh4jid.me)