The Dependency Detonation: The npm Typosquatting Worm and the Software Supply Chain Reckoning
A self-propagating typosquatting worm compromised 12,000+ npm packages through transitive dependenci...
Read more →Articles related to npm.
A self-propagating typosquatting worm compromised 12,000+ npm packages through transitive dependenci...
Read more →The OpenSSF’s deprecation of mutable package registries in favor of hermetic, immutable build grap...
Read more →The convergence of severe npm supply chain attacks and the aggressive shift toward edge rendering an...
Read more →On September 8, 2025, a phishing attack compromised 18 npm packages with 2.6 billion weekly download...
Read more →The 2026 Axios npm supply chain attack and the OpenSSF CRA Readiness Report expose a critical vulner...
Read more →August 2026 exposes a systemic collapse in open-source supply chain trust, highlighted by the "Shai-...
Read more →