DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Deep Dive: TanStack npm supply-chain compromise

Deep Dive: TanStack npm supply-chain compromise

Comments
3 min read
I built a supply chain security scanner in Rust — here's what I learned

I built a supply chain security scanner in Rust — here's what I learned

Comments
4 min read
No, the AI didn't compromise your npm packages. You did.

No, the AI didn't compromise your npm packages. You did.

1
Comments 1
13 min read
I Published My First npm Package — Here's Everything I Wish I Knew

I Published My First npm Package — Here's Everything I Wish I Knew

Comments
5 min read
I Published My First npm Package — Here's Everything I Wish I Knew

I Published My First npm Package — Here's Everything I Wish I Knew

Comments
4 min read
The TanStack Attack: How a Worm Slipped Through the npm Pipeline

The TanStack Attack: How a Worm Slipped Through the npm Pipeline

Comments
6 min read
Your AI keeps recommending these dead npm/PyPI packages — here is the exact migration for each

Your AI keeps recommending these dead npm/PyPI packages — here is the exact migration for each

Comments
9 min read
Attempt to stop npm postinstall scripts from stealing your secrets

Attempt to stop npm postinstall scripts from stealing your secrets

1
Comments
4 min read
npm Is on Fire: Why the Architecture Is the Product

npm Is on Fire: Why the Architecture Is the Product

Comments
10 min read
attw script in CopilotKit codebase.

attw script in CopilotKit codebase.

Comments
3 min read
Desenvolvendo aplicações web com Node.js: do primeiro servidor ao seu próprio roteador de URLs

Desenvolvendo aplicações web com Node.js: do primeiro servidor ao seu próprio roteador de URLs

1
Comments
13 min read
The TanStack npm Attack Shows Why pnpm 11 Matters

The TanStack npm Attack Shows Why pnpm 11 Matters

2
Comments
3 min read
42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

42 @tanstack/* Packages Were Compromised on npm: What Happened, How It Works, and What You Must Do Right Now

Comments
10 min read
LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

LibKill: Scan Your Machine for Compromised npm, pip, and Bun Packages

Comments
3 min read
I got tired of calculating commercial lease billing by hand, so I built a tool

I got tired of calculating commercial lease billing by hand, so I built a tool

Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.