https://mvnpm.org/
mvnpm - Use NPM packages as Maven/Gradle dependencies
Seamlessly integrate NPM packages into Java through Maven and Gradle dependencies. The bridge between NPM and Maven Central.
npm packagesusemavengradledependencies
https://thehackernews.com/2022/05/malicious-npm-packages-target-german.html?m=1
Malicious NPM Packages Target German Companies in Supply Chain Attack
Researchers uncover a new NPM supply-chain attack campaign in which attackers distribute malicious packages to compromise leading German companies.
npm packagesgerman companiesin supplymalicioustarget
https://thehackernews.com/2024/03/over-800-npm-packages-found-with.html?m=1
Over 800 npm Packages Found with Discrepancies, 18 Exploit 'Manifest Confusion'
New report reveals 800+ packages in the npm registry contain hidden code discrepancies.
npm packagesfound
https://dev.wix.com/docs/develop-websites-sdk/code-your-site/developer-environments/packages/npm/about-npm-packages
About npm Packages | SDK
Node Package Manager (npm) is a popular registry of reusable JavaScript code. In npm, each reusable library of code is referred to as a package. When...
about npmpackagessdk
https://dev.to/ibrahimshamma99/asyncdispatch-is-now-on-npm-packages-31k2
asyncdispatch is now on npm packages! - DEV Community
async-dispatch middleware async-dispatch is a middleware can be added with no time to... Tagged with react, javascript, redux.
is nownpm packagesdevcommunity
https://rewards.transmitterstudios.com/
npm Packages That Pay Agents to Integrate Them | Transmitter Studios
AI agents with wallets discover, purchase, and install referral tracking and rewards packages autonomously. Every integration earns a referral code. Every...
npm packagespayagentsintegratetransmitter
https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html?ref=31337infosec.com
North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware
North Korean actors deployed 197 new npm packages delivering evolved OtterCookie and GolangGhost malware through fake interview schemes.
north korean hackersnpm packages
https://docs.npmjs.com/using-npm-packages-in-your-projects/
Using npm packages in your projects | npm Docs
Documentation for the npm registry, website, and command-line interface
npm packagesyour projectsusingdocs
https://advisories.gitlab.com/npm/@finastra/nestjs-proxy/CVE-2022-31069/
Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy...
CVE-2022-31069 Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy: NestJS Proxy is a NestJS module to decorate...
npm packagespotentialauthorizationheaderexposure
https://thehackernews.com/2021/10/malicious-npm-packages-caught-running.html
Malicious NPM Packages Caught Running Cryptominer On Windows, Linux, macOS Devices
New NPM Packages Caught Mining Cryptocurrency on Windows, Linux, macOS Devices
npm packagesmaliciouscaughtrunning
https://unit42.paloaltonetworks.com/tag/npm-packages/
npm packages Archives - Unit 42
npm packagesarchivesunit
https://thehackernews.com/2023/10/over-3-dozen-data-stealing-malicious.html
Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers
Over 30 malicious npm packages discovered in the wild. They're after your sensitive data - SSH keys, Kubernetes configs, and more.
npm packagesdozendatastealing
https://www.infoq.com/news/2019/03/pika-no-configuration-bundler/
Pika Brings Zero-Configuration Bundling and Publishing for NPM Packages - InfoQ
Pika revisits the discovery, bundling, packaging, and publishing of modern web applications. Its discovery module exposes an online search interface retrieving...
zero configurationnpm packagespikabringsbundling
https://thehackernews.com/2025/10/10-npm-packages-caught-stealing.html?m=1
10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux
Ten typosquatted npm packages (Jul 4, 2025) delivered a 24MB PyInstaller info stealer using 4 obfuscation layers; ~9,900 downloads.
npm packagescaught stealing
https://thehackernews.com/2025/08/malicious-pypi-and-npm-packages.html?m=1
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks
PyPI malware termncolor and colorinal downloaded 884 times exploit DLL side-loading, persistence, and C2 communication.
npm packages
https://npm-stat.com/charts.html?package=esprima
npm-stat: download statistics for NPM packages
download statistics for npm packages
download statisticsnpmpackages
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised?ref=andrewshay.me
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
npmdebugchalkpackagescompromised
https://npm-stat.com/charts.html?package=nodejs-smtp
npm-stat: download statistics for NPM packages
download statistics for npm packages
download statisticsnpmpackages
https://securitybrief.asia/story/claude-code-can-leak-secrets-in-public-npm-packages
Claude Code can leak secrets in public npm packages
Hundreds of packages could have exposed API keys and logins after Claude Code saved approved commands in a file npm may publish by default.
claude codein publicleaksecretsnpm
https://thehackernews.com/2026/01/researchers-uncover-nodecordrat-hidden.html?m=1
Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages
researchersuncoverhiddennpmbitcoin
https://pkg.go.dev/github.com/mohamed-gara/terraform-provider-npm/test
test package - github.com/mohamed-gara/terraform-provider-npm/test - Go Packages
test packageterraform providergithubmohamed
https://docs.npmjs.com/managing-team-access-to-organization-packages/
Managing team access to organization packages | npm Docs
Documentation for the npm registry, website, and command-line interface
managing teamaccess toorganizationpackagesnpm
https://thehackernews.com/2026/02/lazarus-campaign-plants-malicious.html?ref=blog.netmanageit.com
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems
North Korea-linked Lazarus campaign spreads malicious npm and PyPI packages via fake crypto job offers, deploying RATs and data-stealing malware.
malicious packageslazaruscampaignplantsnpm
https://docs.npmjs.com/deprecating-and-undeprecating-packages-or-package-versions/
Deprecating and undeprecating packages or package versions | npm Docs
Documentation for the npm registry, website, and command-line interface
deprecatingpackagesversionsnpmdocs
https://docs.npmjs.com/packages-and-modules/getting-packages-from-the-registry/
Getting packages from the registry | npm Docs
Documentation for the npm registry, website, and command-line interface
from thegettingpackagesregistrynpm
https://github.com/npm/read-installed
GitHub - npm/read-installed: Read all the installed packages in a folder, and return a tree...
Read all the installed packages in a folder, and return a tree structure with all the data. - GitHub - npm/read-installed: Read all the installed packages in a...