npm security OSV npm Vulnerabilities: Database, API, and Limits Learn how OSV maps known npm vulnerabilities to exact versions, query the API, scan lockfiles, and understand where advisory data stops.
npm security npm Proxy Registry Security: Architecture Guide A practical guide to npm proxy registry architecture, security limits, policy enforcement, and safe rollout for developers, CI, and coding agents.
npm security package-lock Security: Integrity and Tampering Guide Understand what package-lock.json protects, where integrity hashes stop, and how to review and enforce lockfiles safely in npm projects.
npm security Block Malicious npm Packages in CI: 7 Controls A practical seven-control workflow for stopping known-bad npm packages before they compromise CI runners, credentials, or release jobs.
npm security npm Typosquatting: How to Spot and Stop Fake Packages Learn how npm typosquatting works, spot fake package names before install, and layer controls that reduce developer and CI exposure.
npm security 5 Malicious npm Packages Disclosed September 7 Five newly disclosed malicious npm packages include two command-executing packages and three dependency-confusion beacons. Check exposure and respond safely.
npm security 8 Malicious npm Packages: Check Exposure Now Eight malicious npm packages were disclosed September 7. Check affected versions, rotate exposed keys, rebuild systems, and block known-bad installs.
npm security Secure npm Install: 7 Steps for Safer Dependencies A practical seven-step workflow for safer npm installs across developer machines, CI pipelines, containers, and coding agents.
npm security 13 Malicious Wallet npm Packages: Check Exposure GitHub disclosed 13 wallet-themed npm packages as malware. Check dependency graphs now and treat affected hosts as compromised.
npm security npm Install Scripts Security: Block Malicious Postinstall How npm install scripts became the main npm malware delivery path, what npm v12 blocks by default, and how to allowlist the few packages that need them.
npm security 59 Malicious npm Packages Disclosed Overnight GitHub disclosed 59 malicious npm packages overnight. Check your lockfiles, remove affected packages, and rotate reachable secrets from a clean system.
supply chain security npm Supply Chain Attack: How It Works and How to Stop It Understand how npm supply chain attacks reach trusted installs, where common defenses fail, and which layered controls reduce the risk.