Robuta

https://www.reversinglabs.com/blog/npm-security-shai-hulud
While 2FA and trusted publishing will help, you need tools that give visibility into how packages behave — not just who is publishing.
npm securitynewmeasuresstopnext
https://docs.deno.com/examples/npm/
In-depth documentation, guides, and reference materials for building secure, high-performance JavaScript and TypeScript applications with Deno
importmodulesnpm
https://npmtrends.com/
Which NPM package should you use? Compare packages download stats, bundle sizes, github stars and more. Spot trends, pick the winner.
npmtrendscomparepackagedownloads
https://www.techzine.eu/news/security/136703/npm-hit-again-by-shai-hulud-worm-attack/
Nov 25, 2025 - NPM hit again by Shai-Hulud worm. More than 1,000 package versions compromised. Developers must reset credentials.
techzine globalnpmhitshaiworm
https://opensourceboilerplates.com/boilerplates/yeasin2002-npm-starter
Starter Template for creating NPM Packages
npmstarter
https://www.yagiz.co/using-insecure-npm-defaults/
Jul 13, 2025 - Node Package Manager (npm) provides a set of scripts for developers and package maintainers to maintain the life cycle events of a package.
npm packageusinginsecuremanagerdefaults
https://www.creativosonline.org/alerta-en-npm-bibliotecas-clave-de-javascript-comprometidas.html
Sep 10, 2025 - Malware en NPM afecta bibliotecas de JavaScript: robo cripto mínimo, paquetes deshabilitados y pasos para proteger tus proyectos.
alertaennpmbibliotecasde
https://npm.chart.dev/@nuxt/hints
Nuxt module that shows hints for aspects of your application such as Performance, Security, and more!
nuxthintsnpmdownloadschart
https://www.techzine.nl/nieuws/security/572421/npm-opnieuw-getroffen-door-shai-hulud-worm-aanval/
Nov 25, 2025 - NPM opnieuw getroffen door Shai-Hulud worm. Meer dan 1000 pakketversies gecompromitteerd. Ontwikkelaars moeten credentials resetten.
npmgetroffendoorshaiworm
https://www.yoannfleury.dev/blog/verdaccio-un-registre-de-paquets-npm
Présentation de Verdaccio, un outil alternatif au registry npm pour tester une publication d’un paquet.
unregistredenpmyoann
https://www.11ty.dev/blog/eight-million/
Eight Million npm Downloads! — Eleventy
eightmillionnpmdownloadseleventy
https://safedep.io/npm-supply-chain-attack-targeting-maintainers/
npm supply chain attacks continue. This time targeting @ctrl/tinycolor and multiple other packages with credential stealer malware. In this blog, we will...
supply chain attacknpmexposesprivaterepositories
https://www.reversinglabs.com/blog/faq-shai-hulud-explained
Here's what you need to know about the discovery of the first self-replicating npm worm, which compromised packages with cloud token-stealing malware.
faqshainpmwormattack
https://www.bleepingcomputer.com/news/security/new-wave-of-fake-interviews-use-35-npm-packages-to-spread-malware/
A new wave of North Korea's 'Contagious Interview' campaign is targeting job seekers with malicious npm packages that infect dev's devices with infostealers...
new wavenpm packagesuse
https://www.infoworld.com/article/4111366/deno-adds-tool-to-run-npm-and-jsr-binaries.html
Dec 23, 2025 - Latest update to the Node.js rival also brings more granular control over permissions and a faster, experimental type checker.
denoaddstoolrunnpm
https://codeberg.org/freesewing/freesewing
freesewing - Freesewing's monorepo holding all our NPM packages, including our core library
monorepoholdingnpm
https://docs.npmjs.com/adding-dist-tags-to-packages/
Documentation for the npm registry, website, and command-line interface
addingdisttagspackagesnpm
https://www.csoonline.com/article/4058059/warning-hackers-have-inserted-credential-stealing-code-into-some-npm-libraries.html
Sep 16, 2025 - ‘This is a new frontier’ of malware in open source repositories, says one expert.
warninghackersinsertedcredentialstealing
https://syntax.fm/show/737/jsr-the-new-typescript-package-registry-npm-killer
JSR is a new open source JavaScript package registry focused on modern JavaScript and TypeScript, with advanced features like publishing TypeScript directly,...
package registryjsrnewtypescriptnpm
https://www.theregister.com/2025/11/14/selfreplicating_supplychain_attack_poisons_150k/
Nov 14, 2025 - : Amazon spilled the TEA
crimsfloodnpmjunkpackages
https://www.peerspot.com/products/solarwinds-npm-reviews
Dec 8, 2025 - Read in-depth SolarWinds NPM reviews from real customers and learn about the pricing, features, and more.
solarwindsnpmreviews
https://ryanfreeman.dev/writing/secure-your-websites-with-lets-encrypt-npm-and-cloudflare
SSL/TLS is the encryption standard or protocol which encrypts the session between a website (server) and the browser (client). This protects us from potential...
securewebsitesletencryptnpm
https://travis-ci.community/t/npm-err-spin-is-not-a-valid-npm-option/13797
May 3, 2023 - The latest version of npm no longer accepts deprecated commands and the Travis nodeJS build is pulling this command in from somewhere that isn’t the project...
npmerrspinvalidoption
https://deno.com/blog/npm-on-deno-deploy
Deno Deploy becomes the first isolate serverless platform to natively support more than two million modules on npm.
deno deployannouncingnativenpmsupport
https://github.com/kevinslin/safe-npm?cmid=68bbf2b5-2b82-42a2-af26-84f1fb3dc2e4
Safely install NPM packages. Contribute to kevinslin/safe-npm development by creating an account on GitHub.
githubsafenpminstallpackages
https://deno.com/blog/not-using-npm-specifiers-doing-it-wrong
One common way to import npm packages is with transpile services like esm.sh or unpkg.com, which converts npm modules to esm and hosts them on the web....
usingnpmspecifiers
https://github.blog/engineering/engineering-principles/bringing-npm-registry-services-to-github-codespaces/
Feb 13, 2024 - The npm engineering team recently transitioned to using GitHub Codespaces for local development for npm registry services. This shift to Codespaces has...
registry servicesgithub codespacesbringingnpmblog
https://www.jsdelivr.com/package/npm/jquery
Aug 11, 2025 - A free, fast, and reliable CDN for jquery. JavaScript library for DOM operations
jquery cdnjsdelivrnpmgithub
https://www.riverbed.com/products/npm-plus/
Oct 31, 2025 - Enhance network visibility with Riverbed NPM+. Gain comprehensive observability in cloud, Zero Trust, and remote work environments for optimal performance.
network visibilityriverbednpmenhancedobservability
https://www.aikido.dev/blog/npm-malware-g-wagon-python-stealer-crypto-wallets
npm package ansi-universal-ui delivers GWagon infostealer targeting 100+ crypto wallets, browser credentials, and cloud keys. We analyzed all 10 versions as...
npm packagewagondeployspythonstealer
https://npm.chart.dev/@nuxt/ui
A UI Library for Modern Web Apps, powered by Vue & Tailwind CSS.
nuxtuinpmdownloadschart
https://github.blog/news-insights/product-news/npm-7-is-now-generally-available/
Feb 22, 2022 - We’re announcing version 7 of the npm CLI is now generally available.
generally availablegithub blognpm
https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/
Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new...
npm packagesshaimalwareinfectsleaks
https://deno.com/blog/v1.29
Deno 1.29 ships with many npm compatibility improvements, lots of quality of life improvements and TypeScript 4.9
denocustomnpmregistrysupport
https://blog.risingstack.com/controlling-node-js-security-risk-npm-dependencies/
May 29, 2024 - Using npm packages inevitably exposes you to certain security risks. Follow these points to reduce your security exposure substantially.
node jscontrollingsecurityrisknpm
https://codenotary.com/blog/detecting-the-massive-npm-supply-chain-attack
Learn how to detect the September 2025 NPM supply chain attack that compromised debug, chalk. Includes a bash script to scan your repositories for malicious...
supply chain attackdetectingmassivenpm
https://w3things.com/blog/nodejs-installation-windows/
Beginner's tutorial on how to get started with Node.js (nodejs) and npm installation on Windows.
node jsnodejsnpminstallationwindows
https://npm.chart.dev/@nuxtjs/device
Device detection module for Nuxt
nuxtjsdevicenpmdownloadschart
https://www.jsdelivr.com/package/npm/semantic-ui
Oct 6, 2022 - A free, fast, and reliable CDN for semantic-ui. Semantic empowers designers and developers by creating a shared vocabulary for UI.
semanticuicdnjsdelivrnpm
https://itsmycode.com/unable-to-resolve-dependency-tree-error-when-installing-npm-packages/
Oct 19, 2024 - The Unable to resolve dependency tree error when installing npm packages occurs when you install the node dependencies with the latest version of NPM(v7).
npm packagesunableresolvedependencytree
https://npm.chart.dev/@angular/core
Angular - the core framework
angularcorenpmdownloadschart
https://www.jsdelivr.com/package/npm/ua-parser-js
Dec 9, 2025 - A free, fast, and reliable CDN for ua-parser-js. Detect Browser, Engine, OS, CPU, and Device type/model from User-Agent & Client Hints data. Supports...
uaparserjscdnnpm
https://cycode.com/blog/npm-debug-chalk-supply-chain-attack-the-complete-guide/
Sep 10, 2025 - Learn about the npm debug / chalk Supply-Chain Attack and how it affects popular packages and your projects.
supply chain attackcomplete guidenpmdebugchalk
https://www.jsdelivr.com/package/npm/mark.js?path=dist
Jan 11, 2018 - A free, fast, and reliable CDN for mark.js. Highlight keywords using JavaScript. Intended for every use case. Can e.g. be used to mark text in search results.
markjscdnnpm
https://npm.chart.dev/dayjs-nuxt
Day.JS Module for Nuxt
nuxtnpmdownloadschart
https://forwardemail.net/en/blog/docs/how-npm-packages-billion-downloads-shaped-javascript-ecosystem
In the JavaScript and Node.js world, some packages are essential—downloaded millions of times daily and powering apps worldwide. Behind these tools are...
npm packagesdecadeimpacthit
https://bundlephobia.com/
Bundlephobia helps you find the performance impact of npm packages. Find the size of any javascript package and its effect on your frontend bundle.
sizenpmdependencies
https://npm.chart.dev/@nuxt/scripts
Load third-party scripts with better performance, privacy and DX in Nuxt Apps.
nuxtscriptsnpmdownloadschart
https://sekurak.pl/zlosliwa-kampania-zasmiecania-npm-ponad-43-tysiace-pakietow-indonesianfoods/
Nov 24, 2025 - Na początku listopada Paul McCarty odkrył złośliwą kampanię w menadżerze pakietów npm. Składa się ona z ponad 43 tysięcy pakietów publikowanych...
npm
https://github.blog/news-insights/company-news/npm-is-joining-github/
Apr 15, 2020 - We're excited to announce that npm will be joining GitHub.
npmjoininggithubblog
https://rushjs.io/pages/maintainer/package_managers/
Before you can start installing a JavaScript library, you need to choose which package manager you will use. (Our community loves flexibility and choices, so...
npmvsyarnrush
https://docs.deno.com/runtime/fundamentals/node/
Guide to using Node.js modules and npm packages in Deno. Learn about compatibility features, importing npm packages, and differences between Node.js and Deno...
nodenpmcompatibility
https://gitnation.com/contents/demystifying-npm-what-actually-happens-when-you-install-and-publish
Nov 25, 2025
npmactuallyhappensinstallpublish
https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies
PhantomRaven NPM malware hides in invisible dependencies, silently compromising projects and putting entire software supply chains at risk.
npmmalwarehiddeninvisibledependencies
https://www.devclass.com/development/2022/11/15/nodejs-rival-deno-adds-stable-npm-compatibility-in-effort-to-bridge-module-system-divide/1625995
Jul 31, 2023 - The Deno team has released version 1.28 which “stabilizes npm compatibility,” according to a post today. This is […]
node jsrivaldenoaddsstable
https://benjamincrozat.com/npm-ci
Should you run npm ci or stick with good old npm install? Here's exactly what I learned.
npmcivsinstalldifference
https://www.csoonline.com/article/4117139/from-typos-to-takeovers-inside-the-industrialization-of-npm-supply-chain-attacks.html
Jan 15, 2026 - A dramatic spike in npm-focused intrusions shows how attackers have shifted from opportunistic typosquatting to systematic, credential-driven supply chain...
takeoversinsideindustrializationnpmsupply
https://mostarski.ba/bajka-o-pozoristu-veceras-u-npm-u/
Predstava “Bajka o pozorištu” autora Vladimira Đurđevića, u režiji Ferida Karajice bit će odigrana na Velikoj sceni Narodnog pozorišta (NP) u...
unpmba
https://www.csoonline.com/article/4088529/malicious-npm-package-sneaks-into-github-actions-builds.html
Nov 12, 2025 - The typosquatted “@acitons/artifact” package targeted GitHub’s CI/CD workflows, stealing tokens and publishing malicious artifacts under GitHub’s own...
npm packagegithub actionscso onlinemalicioussneaks
https://github.blog/changelog/2025-10-10-strengthening-npm-security-important-changes-to-authentication-and-token-management/
Sep 30, 2025 - As part of our ongoing commitment to securing the npm ecosystem, we’re implementing the first phase of security improvements outlined in our recent...
npm securityimportantchangesauthenticationtoken
https://npm.chart.dev/@nuxtjs/color-mode
Dark and light mode for Nuxt with auto detection
nuxtjscolormodenpmdownloads
https://www.csoonline.com/article/4090568/worm-flooding-npm-registry-with-token-stealers-still-isnt-under-control-2.html
Nov 17, 2025 - Goal is to steal Tea tokens by inflating package downloads, possibly for profit when the system can be monetized.
spamfloodingnpmregistrytoken
https://npm.chart.dev/@nuxtjs/eslint-module
ESLint module for Nuxt
nuxtjseslintmodulenpmdownloads
https://www.infoworld.com/article/4086207/a-proactive-defense-against-npm-supply-chain-attacks.html
Dec 4, 2025 - Supply chain risk is unavoidable, but not unmanageable. Proactively prevent supply chain attacks by embedding YARA into developer workflows.
supply chain attacksproactive defensenpminfoworld
https://www.csoonline.com/article/4115417/malicious-npm-packages-target-n8n-automation-platform-in-a-supply-chain-attack.html
Jan 12, 2026 - Researchers discovered malicious npm packages posing as n8n integrations, exfiltrating OAuth tokens and API keys from enterprise workflows.
npm packagesautomation platformmalicioustarget
https://css-tricks.com/a-complete-beginners-guide-to-npm/
Jan 20, 2022 - This npm guide helps you understand what npm is, what what makes npm a package manager, and how to use npm from a beginner's view.
free guidecss tricksnpmbeginners
https://www.csoonline.com/article/4095578/new-shai-hulud-worm-spreading-through-npm-github.html
Nov 24, 2025 - The latest version also executes malicious code during the preinstall phase, and is bigger and faster than the first wave, say researchers.
cso onlinenewshaiwormspreading
https://safedep.io/shai-hulud-second-coming-supply-chain-attack/
Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware. Technical analysis reveals...
supply chain attacktechnical analysisshainpm
https://docs.deno.com/examples/backward_compat_with_node_npm/
In-depth documentation, guides, and reference materials for building secure, high-performance JavaScript and TypeScript applications with Deno
compatibilitynodeampnpm
https://npm.chart.dev/@nuxtjs/kinde
Nuxt integration for Kinde authentication
nuxtjskindenpmdownloadschart
https://arethetypeswrong.github.io/
Are The Types Wrong? - Tool for analyzing TypeScript types of npm packages
typeswrongtoolanalyzing
https://sdtimes.com/security/github-details-upcoming-changes-to-improve-security-in-wake-of-shai-hulud-worm-in-npm-ecosystem/
Sep 23, 2025 - Software Development News
upcoming changesimprove securitygithubdetailswake
https://www.11ty.dev/blog/four-million/
Four Million npm Downloads! — Eleventy
fourmillionnpmdownloadseleventy
https://npm.chart.dev/svelte
Cybernetically enhanced web apps
sveltenpmdownloadschart
https://www.csoonline.com/article/4050956/malicious-npm-packages-use-ethereum-blockchain-for-malware-delivery.html
Sep 3, 2025 - Ethereum smart contracts used to hide URL to secondary malware payloads in an attack chain triggered by a malicious GitHub repo.
npm packagesethereum blockchainmalicioususemalware
https://dev.to/usman_awan/the-night-npm-caught-fire-inside-the-2025-javascript-supply-chain-meltdown-52o3
Dec 9, 2025 - 🚨 Recent NPM Supply Chain Attacks — What Happened, Why It Matters, and How to Protect... Tagged with discuss, node, webdev, javascript.
nightnpmcaughtfireinside
https://libraries.io/npm/libraries.io
A libraries.io API client - 3.3.8 - a TypeScript package on npm
npm securitylibrariesio
https://www.itsecurity.pt/news/threats/ataque-massivo-ao-ecossistema-npm-e-github-expoe-segredos-e-falhas-na-supply-chain
Investigadores alertam para ataque massivo à cadeia de fornecimento que afeta npm e GitHub, expondo segredos críticos e comprometendo projetos
shainpmegithub
https://syntax.fm/show/186/potluck-terminal-configs-css-reset-flexbox-freelancing-npm-dependencies-project-hand-off-more
css resetpotluckterminalconfigsflexbox
https://www.aikido.dev/blog/npm-backdoor-lets-hackers-hijack-gambling-outcomes
A targeted npm supply chain attack installs an Express backdoor, enables remote SQL/file access, and rewrites gambling balances while keeping logs consistent.
supply chain attacknpmgamebackendrig
https://www.reversinglabs.com/blog/shai-hulud-worm-npm
RL researchers detected the first self-replicating worm that compromised npm packages with cloud token-stealing malware. Here's what you need to know.
supply chain attackshainpmneed
https://www.infosecurity-magazine.com/news/new-shaihulud-worm-trouble-npm/
Dec 3, 2025 - A new version of the Shai-Hulud worm has infected hundreds of npm packages and caused disruption to global CI/CD workflows
newshaiwormspellstrouble
https://www.python4data.science/en/latest/productive/git/advanced/gitlab/ci-cd/npm.html
npm is a package manager for the JavaScript runtime environment Node.js, and rsync can be used to synchronise the data with the remote server. First steps: Set...
data sciencenpmdeploymentrsyncpython
https://www.nasdaqprivatemarket.com/first-quarter-private-market-report/
Dec 1, 2023 - NPM breaks $30B in total volume transacted and records most programs in a first quarter since its inception. Through quarter close, NPM has surpassed more than...
npmrecordprogramsnasdaq
https://www.veracode.com/blog/npm-account-compromise-the-shai-hulud-worm/
Sep 19, 2025 - Discover how a recent npm account compromise led to the injection of advanced malware with worm-like capabilities, threatening the security of the software...
npmaccountcompromisetrackingquot
https://sveltesociety.dev/video/this-week-in-svelte-ep-116-changelog-e18e-dev-npm-supply-chain-attack-5ebe7957bd3681de
Oct 17, 2025 - Recent updates in the Svelte ecosystem, including a significant supply chain attack.
weeksvelteepchangelogdev
https://changelog.com/friends/111
Over the past two months, we’ve seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and...
npmsiegefeaturing
https://www.jsdelivr.com/package/npm/daisyui
Dec 14, 2025 - A free, fast, and reliable CDN for daisyui. daisyUI 5 - The Tailwind CSS Component Library
cdnjsdelivrnpmgithub
https://npm.chart.dev/vite?primary=violet&gray=cool&theme=light
Native-ESM powered web dev build tool
vitenpmdownloadschart
https://jfrog.com/blog/shai-hulud-npm-supply-chain-attack-new-compromised-packages-detected/
Dec 2, 2025 - Learn about the ongoing Shai Hulud npm supply chain attack, including all currently known compromised packages
supply chain attackshainpmnewcompromised
https://deno.com/blog/v2.3
Deno 2.3 adds new features for deno compile and deno fmt, support for using local npm packages, several performance improvements, and more. Here are the...
npm packagesdenoimprovedcompilelocal
https://deno.com/blog/v1.44
Deno 1.44 adds support for private npm registries, gRPC connections, improved Node.js compat with initial Next.js support, and significant performance...
node jsdenoprivatenpmregistries
https://statically.io/
A free CDN for GitHub, GitLab, Bitbucket, and npm packages. Convert your repository URLs to CDN links instantly.
git repositoriesfreecdnnpmopen
https://cyberint.com/blog/threat-intelligence/the-great-npm-heist-september-2025/
Sep 10, 2025 - The Sept 2025 npm breach: 18+ packages, 2B+ weekly downloads, and crypto-stealing malware. We break down the phishing attack & its impact.
greatnpmheistseptember
https://npm.chart.dev/@nestjs/core
Nest - modern, fast, powerful node.js web framework (@core)
nestjscorenpmdownloadschart
https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/
Sep 23, 2025 - GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
supply chainplansecurenpm
https://dev.to/zhangjintao/from-deprecated-npm-classic-tokens-to-oidc-trusted-publishing-a-cicd-troubleshooting-journey-4h8b
Jan 4, 2026 - In January 2026, I encountered a series of cryptic authentication errors while publishing an npm... Tagged with npm, githubactions, cicd, security.
deprecatednpmclassictokensoidc
https://hackread.com/shai-hulud-npm-worm-supply-chain-attack/
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
shainpmwormimpactsrepos
https://www.11ty.dev/blog/2million/
Two Million npm Downloads! — Eleventy
two millionnpmdownloadseleventy
https://n8d.at/npm-scripts-for-spfx-stop-memorizing-heft-flags/
Feb 4, 2026 - Stop memorizing Heft flags in SPFx 1.22. Learn how npm scripts give you short, reusable build commands that work across every SharePoint Framework project and...
npmscriptsstopheftflags