Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
npm
Follow
Hide
Node Package Manager
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Validando CNPJ de forma definitiva: Conheça a cnpj-universal (JS/TS)
Leandro Gazoli
Leandro Gazoli
Leandro Gazoli
Follow
Apr 7
Validando CNPJ de forma definitiva: Conheça a cnpj-universal (JS/TS)
#
javascript
#
typescript
#
nestjs
#
npm
Comments
Add Comment
2 min read
The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026
Ishaan Pandey
Ishaan Pandey
Ishaan Pandey
Follow
Apr 6
The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026
#
security
#
javascript
#
npm
#
supplychainattack
Comments
Add Comment
16 min read
npm package commitment scores: zod has 139M weekly downloads and one maintainer
Pico
Pico
Pico
Follow
Apr 5
npm package commitment scores: zod has 139M weekly downloads and one maintainer
#
security
#
npm
#
opensource
#
webdev
Comments
Add Comment
4 min read
The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It
Pool Camacho
Pool Camacho
Pool Camacho
Follow
Apr 6
The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It
#
npm
#
security
#
javascript
#
opensource
1
 reaction
Comments
Add Comment
6 min read
The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns
Ethan Kreloff
Ethan Kreloff
Ethan Kreloff
Follow
Apr 4
The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns
#
security
#
javascript
#
npm
#
webdev
Comments
Add Comment
4 min read
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
k-s-h-r
k-s-h-r
k-s-h-r
Follow
Apr 4
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
#
react
#
npm
#
typescript
#
frontend
Comments
Add Comment
5 min read
Why Your AI Coding Agent Keeps Recommending Dead Packages
The BookMaster
The BookMaster
The BookMaster
Follow
Apr 4
Why Your AI Coding Agent Keeps Recommending Dead Packages
#
agents
#
ai
#
npm
#
programming
1
 reaction
Comments
Add Comment
2 min read
I never expected this response ~robot-toast
Pratham Israni
Pratham Israni
Pratham Israni
Follow
May 8
I never expected this response ~robot-toast
#
javascript
#
webdev
#
opensource
#
npm
Comments
Add Comment
2 min read
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
Artyom Kornilov
Artyom Kornilov
Artyom Kornilov
Follow
Apr 4
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
#
npm
#
strapi
#
malware
#
exfiltration
Comments
Add Comment
7 min read
Supply Chain Security measures
0xkoji
0xkoji
0xkoji
Follow
Apr 3
Supply Chain Security measures
#
security
#
npm
#
uv
#
githubactions
Comments
Add Comment
1 min read
Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm
Kazu
Kazu
Kazu
Follow
Apr 14
Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm
#
cli
#
github
#
go
#
npm
Comments
Add Comment
5 min read
npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see
Juan Torchia
Juan Torchia
Juan Torchia
Follow
May 7
npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see
#
english
#
typescript
#
npm
#
devops
1
 reaction
Comments
Add Comment
9 min read
npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve
Juan Torchia
Juan Torchia
Juan Torchia
Follow
May 7
npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve
#
spanish
#
espanol
#
typescript
#
npm
1
 reaction
Comments
Add Comment
10 min read
The Axios/npm Incident & Why AI Won’t Replace Devs
Cyber Janitor
Cyber Janitor
Cyber Janitor
Follow
Apr 4
The Axios/npm Incident & Why AI Won’t Replace Devs
#
ai
#
javascript
#
npm
#
security
Comments
Add Comment
1 min read
I built an npm malware scanner and found 21 malicious packages in 24 hours
Yuri Borges
Yuri Borges
Yuri Borges
Follow
Apr 3
I built an npm malware scanner and found 21 malicious packages in 24 hours
#
security
#
npm
#
javascript
#
opensource
Comments
1
 comment
1 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account