DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
I built an npm malware scanner in Rust because npm audit isn't enough

I built an npm malware scanner in Rust because npm audit isn't enough

1
Comments 2
3 min read
MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent

MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent

Comments
5 min read
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components

I built Material Symbols SVG, an icon library for using Material Symbols as SVG components

Comments
5 min read
npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026

npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026

Comments
5 min read
Axios got compromised. They attacked the human, not code.

Axios got compromised. They attacked the human, not code.

3
Comments
4 min read
Why Your AI Coding Agent Keeps Recommending Dead Packages

Why Your AI Coding Agent Keeps Recommending Dead Packages

Comments
2 min read
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution

Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution

Comments
7 min read
Supply Chain Security measures

Supply Chain Security measures

Comments
1 min read
I'm 12 and I built a 2KB 0 dependency alternative to CASL!

I'm 12 and I built a 2KB 0 dependency alternative to CASL!

Comments
1 min read
The Axios/npm Incident & Why AI Won’t Replace Devs

The Axios/npm Incident & Why AI Won’t Replace Devs

Comments
1 min read
I built an npm malware scanner and found 21 malicious packages in 24 hours

I built an npm malware scanner and found 21 malicious packages in 24 hours

Comments 1
1 min read
How the axios@1.14.1 supply chain attack worked (and how to protect yourself)

How the axios@1.14.1 supply chain attack worked (and how to protect yourself)

Comments
4 min read
What the Axios npm Compromise Means for MCP Server Maintainers

What the Axios npm Compromise Means for MCP Server Maintainers

Comments
4 min read
How to Finally (and Iteratively) Kill Every Last 'npm audit'

How to Finally (and Iteratively) Kill Every Last 'npm audit'

Comments
3 min read
The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.

The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.

Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.