DEV Community

npm

Node Package Manager

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Copy-Paste Components vs npm Packages: shadcn/ui vs Ninna UI in 2026

Copy-Paste Components vs npm Packages: shadcn/ui vs Ninna UI in 2026

Comments
5 min read
Compromised npm Maintainer Account Publishes Malicious Axios Versions with Backdoor via `plain-crypto-js` Dependency

Compromised npm Maintainer Account Publishes Malicious Axios Versions with Backdoor via `plain-crypto-js` Dependency

Comments
11 min read
The axios Supply Chain Attack Just Proved Why Static Analysis Matters More Than Ever

The axios Supply Chain Attack Just Proved Why Static Analysis Matters More Than Ever

Comments
4 min read
npm's Implicit Dependency Execution Exposes Users to Security Risks: Explicit Confirmation Needed

npm's Implicit Dependency Execution Exposes Users to Security Risks: Explicit Confirmation Needed

Comments
9 min read
Whole-laptop scanner for the Axios supply chain attack

Whole-laptop scanner for the Axios supply chain attack

Comments
3 min read
⚠️ Axios Supply Chain Attack — If You Installed Yesterday, Check This

⚠️ Axios Supply Chain Attack — If You Installed Yesterday, Check This

Comments 1
2 min read
axios Was Compromised on npm — What Happened, How It Works, and What You Must Do Right Now

axios Was Compromised on npm — What Happened, How It Works, and What You Must Do Right Now

2
Comments
9 min read
[Axios Hacked] How .npmrc Can Protect Your Node.js Projects from Supply Chain Attacks??

[Axios Hacked] How .npmrc Can Protect Your Node.js Projects from Supply Chain Attacks??

5
Comments 2
2 min read
API 개발자를 위한 NPM 의존성 보안 완벽 가이드: 공급망 보안 강화

API 개발자를 위한 NPM 의존성 보안 완벽 가이드: 공급망 보안 강화

Comments
3 min read
Made a new software: BetterYoutube Desktop!

Made a new software: BetterYoutube Desktop!

1
Comments
1 min read
A fully-featured React loader overlay component

A fully-featured React loader overlay component

Comments
1 min read
Welcome to Transitive Dependency Hell

Welcome to Transitive Dependency Hell

Comments
5 min read
Blind `npm install` Execution Risks Security Vulnerabilities: Review Lockfiles to Mitigate Threats

Blind `npm install` Execution Risks Security Vulnerabilities: Review Lockfiles to Mitigate Threats

Comments
10 min read
The Axios NPM Package Compromise: Lessons for Startups and Tech Firms

The Axios NPM Package Compromise: Lessons for Startups and Tech Firms

1
Comments 1
5 min read
axios Got Hacked. If You Ran npm install Yesterday, Read This Now.

axios Got Hacked. If You Ran npm install Yesterday, Read This Now.

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.