Skip to content

project

npm registry

The default public registry for JavaScript and Node.js packages, hosting millions of open-source modules installed and published via the npm command-line tool.

Known aliases

  • node package manager
  • NPM
  • npm audit
  • npm ci
  • npm CLI
  • npm exec
  • npm install
  • npm install -g
  • npmjs
  • npmjs.com
  • npm pack
  • npm publish
  • npm registry
  • npm v12
  • package.json
  • package-lock.json
  • public npm
  • public npm registry
  • registry.npmjs.org

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

A static denylist stopped one more prompt injection than no protection in a coding-agent study

Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
build1 publisher

Live MCP servers trail the stateless 2026-07-28 revision that clients already ship

Pennyforge found 7 of 72 responding MCP registry endpoints on the stateless 2026-07-28 revision that clients already ship. Servers answer with whatever in-range version a client offers, so a client learns what one supports only by offering the newest revision and reading the reply.

Publishers:dev.to

Reality

Evidence55
Adoption9
Hype gap+15
Incentives
Insufficient
Confidence45
build1 publisher

Fake Polymarket copy-trading bots hid key stealers in their npm dependencies

One attacker pushed more than twenty malicious GitHub repos from a hijacked account in February, several posing as Polymarket copy-trading bots. Garnet's maintainer published a fifteen-minute checklist for tracing what a bot does with the one signing key it needs.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+20
Incentives70
Confidence40
security1 publisher

TeamPCP's package attacks reused the stolen-token techniques of S1ngularity and Shai-Hulud

Two TeamPCP-linked actors are under arrest after package compromises that ReversingLabs says caused a suspected hundreds of millions of dollars in damages. The waves since September 2025 began with a stolen publishing credential and reached victims through updates their own pipelines installed.

Reality

Evidence35
Adoption
Insufficient
Hype gap+25
Incentives75
Confidence35
security3 publishers

Two actions-cool GitHub Actions resumed running the Mini Shai-Hulud stealer after coming back online

Two actions-cool GitHub Actions hijacked on May 18 came back online on September 16, still serving the Mini Shai-Hulud stealer to tag-pinned workflows. Only workflows pinned to a pre-May 18 commit SHA escaped; the rest have CI secrets to rotate.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 47%
Investor
Investor 10%

Reality

Evidence60
Adoption40
Hype gap+15
Incentives30
Confidence65
build1 publisher

Poisoned vite.config.js turns git pull and npm run build into malware

Malware that steals a developer's Git credentials force-pushes a poisoned vite.config.js to every reachable branch, a dozen rewritten in a minute in one case. A routine git pull and build then runs it, and dependency scanners never see the change.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50

Earlier coverage

  1. Mirage Kitten ships Node.js RATs through fake LinkedIn coding challenges

    Security · September 1, 2026 · 4 publishers

  2. Compromised MemOS packages scan for developer tokens the moment Python imports them

    Build · September 25, 2026 · 1 publisher

  3. Kothamine RAT tunnels its commands through Tailscale's tailcat

    Security · September 25, 2026 · 1 publisher

  4. The PhantomRaven operator turned stolen CI/CD secrets into bug bounty payouts, CrowdStrike says

    Security · September 18, 2026 · 2 publishers

  5. Thirteen npm packages ship a stripped-down stealer that uploads Chrome's extension storage wholesale

    Security · September 18, 2026 · 1 publisher

  6. PhantomRaven hid its credential stealer in an npm dependency that scanners never fetch

    Security · September 21, 2026 · 2 publishers

  7. Malicious npm package indexed-btree fires its loader from a runtime library call

    Security · September 20, 2026 · 3 publishers

  8. Joint advisory pins WaterPlum's fake recruiters to North Korea's 313 General Bureau

    Security · September 18, 2026 · 8 publishers

  9. Attacker copied 170 CrowdSec repositories with a departed employee's still-live GitHub token

    Security · September 19, 2026 · 7 publishers

  10. A pushed commit pulled MemTensor's npm and PyPI publish tokens out of its own release workflow

    Security · September 23, 2026 · 2 publishers

  11. JFrog moves Xray's download blocking into a separately priced Curation seat by November 2026

    Product · September 24, 2026 · 1 publisher

  12. GitHub lost 3,800 internal repos to code running with its editor's permissions

    Build · September 24, 2026 · 1 publisher

  13. An ex-employee's live OAuth token let strangers copy 170 CrowdSec repositories in nine minutes

    Product · September 24, 2026 · 1 publisher

  14. A DPRK-linked package campaign has started publishing to HashiCorp's Terraform Registry

    Security · September 23, 2026 · 1 publisher

  15. Graphalgo malware in a Terraform provider stays inert until two variables hash to one digest

    Build · September 23, 2026 · 1 publisher

  16. Cycode blocks a package for its age at the same point it blocks known malware

    Build · September 23, 2026 · 1 publisher

  17. depproof: unmaintained flag doesn't change the remedy; only 3 of 933 findings lacked a fix version

    Build · September 23, 2026 · 1 publisher

  18. Five of eight DuckDuckGo MCP servers failed calls on the same twelve back-to-back queries

    Build · September 23, 2026 · 1 publisher

  19. Prismor checks every AI coding agent tool call against policy before it runs

    Security · September 22, 2026 · 1 publisher

  20. V8's ToBoolean path leaks the secret bit that constant-time-js was written to hide

    Product · September 22, 2026 · 1 publisher

  21. DuckDB-Wasm writes a real .duckdb file with a WAL into the browser's OPFS

    Product · September 22, 2026 · 1 publisher

  22. npm keeps accepting write tokens after you switch on OIDC trusted publishing

    Product · September 22, 2026 · 1 publisher

  23. Deno desktop's default backend draws your UI with whatever engine the host already ships

    Build · September 22, 2026 · 1 publisher

  24. A departed employee's GitHub OAuth token cloned about 170 CrowdSec repositories in nine minutes

    Build · September 22, 2026 · 2 publishers

  25. A fake Twilio bug-bounty probe went up on npm eleven times on August 14

    Security · September 22, 2026 · 1 publisher

  26. npm ci OOM-killed a 1.6 GB production box while Cloudflare reported 521 and 522

    Build · September 22, 2026 · 1 publisher

  27. In one worked example, a coding agent waits 93 percent of its cycle on CI

    Build · September 22, 2026 · 1 publisher

  28. A kprobe on tcp_connect killed an npm postinstall's curl inside AWS CodeBuild

    Build · September 21, 2026 · 1 publisher

  29. npm is the only one of three registries that will tell an API client who to pay

    Build · September 21, 2026 · 1 publisher

  30. Adding .npmignore to drop test fixtures revoked a year of .gitignore exclusions

    Build · September 20, 2026 · 1 publisher

  31. DPRK malware came back in the next release of fetch-page-assets after npm's June takedown

    Security · September 20, 2026 · 1 publisher

  32. Malicious npm package fires its loader from inside BTree.prototype.set()

    Build · September 20, 2026 · 1 publisher

  33. Ten packages each ship a test that would declare the package unnecessary

    Build · September 19, 2026 · 1 publisher

  34. AI Employee runs secret and dependency checks in plain code before any model sees the diff

    Build · September 19, 2026 · 1 publisher

  35. Trusting the repository author in VS Code runs the fake recruiter's task file

    Build · September 19, 2026 · 1 publisher

  36. Four governments pin $10.7m of crypto theft on fake recruiter coding tests

    Invest · September 19, 2026 · 1 publisher

  37. A skills.lock file puts Agent Skills behind the same digest check as an npm dependency

    Build · September 19, 2026 · 1 publisher

  38. A local proxy convinces the ChatGPT desktop app it is still talking to OpenAI

    Build · September 19, 2026 · 1 publisher

  39. Unauthenticated SAP attackers hit memory corruption before any login check

    Security · September 18, 2026 · 1 publisher

  40. Four governments trace 30,000 infected devices to fake interview coding tasks

    Build · September 18, 2026 · 1 publisher