Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
npm
Follow
Hide
Node Package Manager
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Why Your AI Coding Agent Keeps Recommending Dead Packages
The BookMaster
The BookMaster
The BookMaster
Follow
Apr 4
Why Your AI Coding Agent Keeps Recommending Dead Packages
#
agents
#
ai
#
npm
#
programming
1
 reaction
Comments
Add Comment
2 min read
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
Artyom Kornilov
Artyom Kornilov
Artyom Kornilov
Follow
Apr 4
Malicious npm Packages Disguised as Strapi Plugins Enable Data Exfiltration and Remote Code Execution
#
npm
#
strapi
#
malware
#
exfiltration
Comments
Add Comment
7 min read
pnpm vs npm vs yarn vs bun: The Real Comparison Nobody Gives You in 2025
Juan Torchia
Juan Torchia
Juan Torchia
Follow
Apr 17
pnpm vs npm vs yarn vs bun: The Real Comparison Nobody Gives You in 2025
#
english
#
technology
#
pnpm
#
npm
Comments
Add Comment
6 min read
Supply Chain Security measures
0xkoji
0xkoji
0xkoji
Follow
Apr 3
Supply Chain Security measures
#
security
#
npm
#
uv
#
githubactions
Comments
Add Comment
1 min read
Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm
Kazu
Kazu
Kazu
Follow
Apr 14
Shipping a Go CLI to Every Ecosystem: GitHub Releases, Homebrew, and npm
#
cli
#
github
#
go
#
npm
Comments
Add Comment
5 min read
The Axios/npm Incident & Why AI Won’t Replace Devs
Cyber Janitor
Cyber Janitor
Cyber Janitor
Follow
Apr 4
The Axios/npm Incident & Why AI Won’t Replace Devs
#
ai
#
javascript
#
npm
#
security
Comments
Add Comment
1 min read
I built an npm malware scanner and found 21 malicious packages in 24 hours
Yuri Borges
Yuri Borges
Yuri Borges
Follow
Apr 3
I built an npm malware scanner and found 21 malicious packages in 24 hours
#
security
#
npm
#
javascript
#
opensource
Comments
1
 comment
1 min read
How the axios@1.14.1 supply chain attack worked (and how to protect yourself)
bigjenkie
bigjenkie
bigjenkie
Follow
Apr 3
How the axios@1.14.1 supply chain attack worked (and how to protect yourself)
#
javascript
#
opensource
#
security
#
npm
Comments
Add Comment
4 min read
What the Axios npm Compromise Means for MCP Server Maintainers
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Follow
Apr 3
What the Axios npm Compromise Means for MCP Server Maintainers
#
security
#
mcp
#
npm
#
supplychain
Comments
Add Comment
4 min read
How to Finally (and Iteratively) Kill Every Last 'npm audit'
Tony Metzidis
Tony Metzidis
Tony Metzidis
Follow
Apr 2
How to Finally (and Iteratively) Kill Every Last 'npm audit'
#
security
#
automation
#
npm
#
node
Comments
Add Comment
3 min read
.me
Sui Gn
Sui Gn
Sui Gn
Follow
Apr 7
.me
#
showdev
#
javascript
#
npm
#
typescript
4
 reactions
Comments
Add Comment
6 min read
The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.
Skip Middleton
Skip Middleton
Skip Middleton
Follow
Apr 2
The Axios Incident Was an Execution Failure. Here Is the Architecture That Prevents It.
#
npm
#
axios
#
openclaw
#
devsec
Comments
Add Comment
2 min read
How I Would Have Stopped the March 2026 Axios Supply Chain Attack (Free Tool Inside)
0n
0n
0n
Follow
Apr 2
How I Would Have Stopped the March 2026 Axios Supply Chain Attack (Free Tool Inside)
#
security
#
npm
#
ai
#
opensource
Comments
Add Comment
2 min read
I Built a CLI That Shows the Real Cost of Your node_modules (Size + Security + Age)
Profiterole
Profiterole
Profiterole
Follow
Apr 2
I Built a CLI That Shows the Real Cost of Your node_modules (Size + Security + Age)
#
node
#
npm
#
javascript
#
security
Comments
Add Comment
3 min read
I built a tiny hook to solve the missing navigation guard in Next.js App Router
Gichan
Gichan
Gichan
Follow
Apr 3
I built a tiny hook to solve the missing navigation guard in Next.js App Router
#
react
#
nextjs
#
typescript
#
npm
1
 reaction
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account