Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
npm
Node Package Manager
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Beyond the Event Loop: Tracking Slow I/O in Production Node.js
Bill Tu
Bill Tu
Bill Tu
Follow
Apr 7
Beyond the Event Loop: Tracking Slow I/O in Production Node.js
#
javascript
#
npm
#
node
Comments
Add Comment
8 min read
Validando CNPJ de forma definitiva: Conheça a cnpj-universal (JS/TS)
Leandro Gazoli
Leandro Gazoli
Leandro Gazoli
Follow
Apr 7
Validando CNPJ de forma definitiva: Conheça a cnpj-universal (JS/TS)
#
javascript
#
typescript
#
nestjs
#
npm
Comments
Add Comment
2 min read
The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026
Ishaan Pandey
Ishaan Pandey
Ishaan Pandey
Follow
Apr 6
The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026
#
security
#
javascript
#
npm
#
supplychainattack
Comments
Add Comment
16 min read
The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It
Pool Camacho
Pool Camacho
Pool Camacho
Follow
Apr 6
The Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It
#
npm
#
security
#
javascript
#
opensource
1
 reaction
Comments
Add Comment
6 min read
The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns
Ethan Kreloff
Ethan Kreloff
Ethan Kreloff
Follow
Apr 4
The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns
#
security
#
javascript
#
npm
#
webdev
Comments
Add Comment
4 min read
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
k-s-h-r
k-s-h-r
k-s-h-r
Follow
Apr 4
I built Material Symbols SVG, an icon library for using Material Symbols as SVG components
#
react
#
npm
#
typescript
#
frontend
Comments
Add Comment
5 min read
Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks
Juan Torchia
Juan Torchia
Juan Torchia
Follow
May 8
Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks
#
english
#
npm
#
node
#
devops
Comments
Add Comment
9 min read
Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen
Juan Torchia
Juan Torchia
Juan Torchia
Follow
May 8
Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen
#
spanish
#
espanol
#
npm
#
node
Comments
Add Comment
10 min read
Why Your LLM Agent Forgot What It Did 5 Steps Ago
Saran S
Saran S
Saran S
Follow
for
Dopove
May 8
Why Your LLM Agent Forgot What It Did 5 Steps Ago
#
ai
#
python
#
npm
#
agents
1
 reaction
Comments
1
 comment
4 min read
Stop Shipping Broken Env Configs — I Built a Fix
Rohan Mirjankar
Rohan Mirjankar
Rohan Mirjankar
Follow
May 8
Stop Shipping Broken Env Configs — I Built a Fix
#
npm
#
javascript
#
node
#
webdev
1
 reaction
Comments
Add Comment
2 min read
AGENTS.md moved AI performance up a model tier. Package trust needs the same.
Pico
Pico
Pico
Follow
May 8
AGENTS.md moved AI performance up a model tier. Package trust needs the same.
#
npm
#
security
#
javascript
#
supplychain
Comments
Add Comment
2 min read
Why Your AI Coding Agent Keeps Recommending Dead Packages
The BookMaster
The BookMaster
The BookMaster
Follow
Apr 4
Why Your AI Coding Agent Keeps Recommending Dead Packages
#
agents
#
ai
#
npm
#
programming
1
 reaction
Comments
Add Comment
2 min read
I never expected this response ~robot-toast
Pratham Israni
Pratham Israni
Pratham Israni
Follow
May 8
I never expected this response ~robot-toast
#
javascript
#
webdev
#
opensource
#
npm
Comments
Add Comment
2 min read
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
Artyom Kornilov
Artyom Kornilov
Artyom Kornilov
Follow
Apr 4
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
#
npm
#
strapi
#
malware
#
exfiltration
Comments
Add Comment
7 min read
The Axios/npm Incident & Why AI Won’t Replace Devs
Cyber Janitor
Cyber Janitor
Cyber Janitor
Follow
Apr 4
The Axios/npm Incident & Why AI Won’t Replace Devs
#
ai
#
javascript
#
npm
#
security
Comments
Add Comment
1 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account