Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
npm
Follow
Hide
Node Package Manager
Posts
Left menu
👋
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
512,000 Lines of Claude Code Leaked Through a Single .npmignore Mistake
jidonglab
jidonglab
jidonglab
Follow
Apr 2
512,000 Lines of Claude Code Leaked Through a Single .npmignore Mistake
#
news
#
ai
#
npm
#
security
Comments
Add Comment
7 min read
The axios Attack Was a Wake-Up Call. Your AI Agent Just Ran npm install Without Asking You.
CyborgNinja1
CyborgNinja1
CyborgNinja1
Follow
Apr 2
The axios Attack Was a Wake-Up Call. Your AI Agent Just Ran npm install Without Asking You.
#
security
#
javascript
#
ai
#
npm
Comments
Add Comment
4 min read
Copy-Paste Components vs npm Packages: shadcn/ui vs Ninna UI in 2026
Cihan Koç
Cihan Koç
Cihan Koç
Follow
Apr 1
Copy-Paste Components vs npm Packages: shadcn/ui vs Ninna UI in 2026
#
frontend
#
npm
#
react
#
ui
Comments
Add Comment
5 min read
Compromised npm Maintainer Account Publishes Malicious Axios Versions with Backdoor via `plain-crypto-js` Dependency
Pavel Kostromin
Pavel Kostromin
Pavel Kostromin
Follow
Apr 1
Compromised npm Maintainer Account Publishes Malicious Axios Versions with Backdoor via `plain-crypto-js` Dependency
#
npm
#
security
#
axios
#
backdoor
Comments
Add Comment
11 min read
The axios Supply Chain Attack Just Proved Why Static Analysis Matters More Than Ever
ayame0328
ayame0328
ayame0328
Follow
Apr 1
The axios Supply Chain Attack Just Proved Why Static Analysis Matters More Than Ever
#
news
#
javascript
#
npm
#
security
Comments
Add Comment
4 min read
npm's Implicit Dependency Execution Exposes Users to Security Risks: Explicit Confirmation Needed
Marina Kovalchuk
Marina Kovalchuk
Marina Kovalchuk
Follow
Apr 1
npm's Implicit Dependency Execution Exposes Users to Security Risks: Explicit Confirmation Needed
#
npm
#
security
#
dependencies
#
malware
Comments
Add Comment
9 min read
Whole-laptop scanner for the Axios supply chain attack
Стас Журавель
Стас Журавель
Стас Журавель
Follow
Apr 1
Whole-laptop scanner for the Axios supply chain attack
#
javascript
#
npm
#
security
#
tooling
Comments
Add Comment
3 min read
⚠️ Axios Supply Chain Attack — If You Installed Yesterday, Check This
AdarshGzz...
AdarshGzz...
AdarshGzz...
Follow
Apr 1
⚠️ Axios Supply Chain Attack — If You Installed Yesterday, Check This
#
webdev
#
javascript
#
node
#
npm
Comments
1
comment
2 min read
axios Was Compromised on npm — What Happened, How It Works, and What You Must Do Right Now
VIKAS
VIKAS
VIKAS
Follow
Apr 1
axios Was Compromised on npm — What Happened, How It Works, and What You Must Do Right Now
#
security
#
javascript
#
npm
#
webdev
2
reactions
Comments
Add Comment
9 min read
[Axios Hacked] How .npmrc Can Protect Your Node.js Projects from Supply Chain Attacks??
0x41414141
0x41414141
0x41414141
Follow
Apr 1
[Axios Hacked] How .npmrc Can Protect Your Node.js Projects from Supply Chain Attacks??
#
discuss
#
npm
#
ai
#
webdev
5
reactions
Comments
2
comments
2 min read
API 개발자를 위한 NPM 의존성 보안 완벽 가이드: 공급망 보안 강화
Rihpig
Rihpig
Rihpig
Follow
Apr 1
API 개발자를 위한 NPM 의존성 보안 완벽 가이드: 공급망 보안 강화
#
api
#
node
#
npm
#
security
Comments
Add Comment
3 min read
A fully-featured React loader overlay component
SwapnilH Patil
SwapnilH Patil
SwapnilH Patil
Follow
Apr 1
A fully-featured React loader overlay component
#
react
#
javascript
#
opensource
#
npm
Comments
Add Comment
1 min read
Welcome to Transitive Dependency Hell
RoseSecurity
RoseSecurity
RoseSecurity
Follow
Mar 31
Welcome to Transitive Dependency Hell
#
javascript
#
npm
#
security
Comments
Add Comment
5 min read
Blind `npm install` Execution Risks Security Vulnerabilities: Review Lockfiles to Mitigate Threats
Denis Lavrentyev
Denis Lavrentyev
Denis Lavrentyev
Follow
Apr 1
Blind `npm install` Execution Risks Security Vulnerabilities: Review Lockfiles to Mitigate Threats
#
npm
#
security
#
dependencies
#
lockfiles
Comments
Add Comment
10 min read
The Axios NPM Package Compromise: Lessons for Startups and Tech Firms
David Díaz
David Díaz
David Díaz
Follow
Apr 1
The Axios NPM Package Compromise: Lessons for Startups and Tech Firms
#
axios
#
npm
#
security
#
startup
1
reaction
Comments
1
comment
5 min read
👋
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account