Hackernews posts about NPM
NPM is a package manager for JavaScript that allows developers to easily install and manage dependencies in their projects, serving as a central registry for millions of open-source packages.
Related:
Ledger
- Axios compromised on NPM – Malicious versions drop remote access trojan (www.stepsecurity.io)
- Post Mortem: axios NPM supply chain compromise (github.com)
- Claude Code full source code leaked on NPM (github.com)
- North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package (cloud.google.com)
- Show HN: Llmpm – NPM for LLMs (www.llmpm.co)
- 1 Click authentication with new NPM package (www.npmjs.com)
- Malicious NPM Packages Found in React Native – 130K+ Monthly Downloads Hit (www.stepsecurity.io)
- Exploring NPM's Dependency Blast Radius: Visualization of the Top 1K (realarcherl.github.io)
- Top NPM package backdoored to drop dirty RAT on dev machines (www.theregister.com)
- NPM's Defaults Are Bad (nesbitt.io)
- TeamPCP deploys CanisterWorm on NPM following Trivy compromise (www.aikido.dev)
- Axios NPM Package Supply Chain Hack (www.bleepingcomputer.com)