Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
npm
Follow
Hide
Node Package Manager
Posts
Left menu
👋
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
I built an npm malware scanner in Rust because npm audit isn't enough
Pool Camacho
Pool Camacho
Pool Camacho
Follow
Apr 3
I built an npm malware scanner in Rust because npm audit isn't enough
#
npm
#
security
#
rust
#
opensource
1
reaction
Comments
2
comments
3 min read
MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent
Toni Antunovic
Toni Antunovic
Toni Antunovic
Follow
Apr 4
MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent
#
security
#
npm
#
javascript
#
devops
Comments
Add Comment
5 min read
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
k-s-h-r
k-s-h-r
k-s-h-r
Follow
Apr 4
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
#
react
#
npm
#
typescript
#
frontend
Comments
Add Comment
5 min read
npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026
Toni Antunovic
Toni Antunovic
Toni Antunovic
Follow
Apr 4
npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026
#
security
#
npm
#
devops
#
javascript
Comments
Add Comment
5 min read
Axios got compromised. They attacked the human, not code.
DHg
DHg
DHg
Follow
Apr 4
Axios got compromised. They attacked the human, not code.
#
npm
#
security
#
axios
#
opensource
3
reactions
Comments
Add Comment
4 min read
Why Your AI Coding Agent Keeps Recommending Dead Packages
The BookMaster
The BookMaster
The BookMaster
Follow
Apr 4
Why Your AI Coding Agent Keeps Recommending Dead Packages
#
agents
#
ai
#
npm
#
programming
Comments
Add Comment
2 min read
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
Artyom Kornilov
Artyom Kornilov
Artyom Kornilov
Follow
Apr 4
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
#
npm
#
strapi
#
malware
#
exfiltration
Comments
Add Comment
7 min read
Supply Chain Security measures
0xkoji
0xkoji
0xkoji
Follow
Apr 3
Supply Chain Security measures
#
security
#
npm
#
uv
#
githubactions
Comments
Add Comment
1 min read
I'm 12 and I built a 2KB 0 dependency alternative to CASL!
CreeperGuy14
CreeperGuy14
CreeperGuy14
Follow
Apr 3
I'm 12 and I built a 2KB 0 dependency alternative to CASL!
#
showdev
#
npm
#
typescript
#
node
Comments
Add Comment
1 min read
The Axios/npm Incident & Why AI Won’t Replace Devs
Cyber Janitor
Cyber Janitor
Cyber Janitor
Follow
Apr 4
The Axios/npm Incident & Why AI Won’t Replace Devs
#
ai
#
javascript
#
npm
#
security
Comments
Add Comment
1 min read
I built an npm malware scanner and found 21 malicious packages in 24 hours
Yuri Borges
Yuri Borges
Yuri Borges
Follow
Apr 3
I built an npm malware scanner and found 21 malicious packages in 24 hours
#
security
#
npm
#
javascript
#
opensource
Comments
1
comment
1 min read
How the axios@1.14.1 supply chain attack worked (and how to protect yourself)
bigjenkie
bigjenkie
bigjenkie
Follow
Apr 3
How the axios@1.14.1 supply chain attack worked (and how to protect yourself)
#
javascript
#
opensource
#
security
#
npm
Comments
Add Comment
4 min read
What the Axios npm Compromise Means for MCP Server Maintainers
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Follow
Apr 3
What the Axios npm Compromise Means for MCP Server Maintainers
#
security
#
mcp
#
npm
#
supplychain
Comments
Add Comment
4 min read
How to Finally (and Iteratively) Kill Every Last 'npm audit'
Tony Metzidis
Tony Metzidis
Tony Metzidis
Follow
Apr 2
How to Finally (and Iteratively) Kill Every Last 'npm audit'
#
security
#
automation
#
npm
#
node
Comments
Add Comment
3 min read
The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.
Skip Middleton
Skip Middleton
Skip Middleton
Follow
Apr 2
The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.
#
npm
#
axios
#
openclaw
#
devsec
Comments
Add Comment
2 min read
👋
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account