#npmjs

Nate Silvans@hachyderm.io
2025-04-01

@cloudflare Cloudflare, are you blocking anything with the word “camel” in it? Such as NPM modules that have `camelcase` in the name?

#outage #npmjs #cloudflare #camel

2025-03-28

Looking for a simple way to provide a compressed archive from a web application with the requirement to create the archive in the browser, not on the server.

- JSZip: 12 (transitive) dependencies
- tar-js: 0 dependencies

While zip may be more common, the 0-dependencies is a unique selling point for me!

#javascript #zip #tar #programming #npmjs

2025-02-01

How many vanilla.js/zero-dependency reusable components are there on npmjs.com? I can easily write my own components for simple things, like a Dark Mode switch, as plain old JavaScript classes that directly manipulate the DOM. Why can't I simply add a bunch of these components to my project and use import-maps to load them?

#npmjs #vanillajs #javascript

2024-12-09

i just explained that i don't want to pull in a dependency from #npmjs because george washington taught me to avoid entangling alliances, how's your monday goin

2024-12-08

hmm, i know it's early but is npmjs showing 404s for a lot of packages right now? seems so

every "popular library" on npmjs.com/ is a 404 if clicked

#npmjs #npm

2024-08-06

In the last 6 months, roughly 70% of new #npm packages were #spam. What does this mean for supply chain security?

At Black Hat USA? Find us in Startup City booth SC203!

#npmjs #node #javascript #typescript #infosec #opensource

blog.phylum.io/the-great-npm-g

2024-07-08

Advanced threat actors have not let up on their attacks against the software supply chain. We catalog recent attacks from North Korean state actors in our new blog post!

#npm #javascript #typescript #malware #cybersecurity #npmjs

blog.phylum.io/new-tactics-fro

2024-07-04

Supply chain attacks come in all shapes and sizes. Today Phylum Research discusses its discovery of malicious #jQuery files in #npm.

blog.phylum.io/persistent-npm-

#javascript #opensource #sbom #js #npmjs #node #cybersecurity #softwaredevelopment #software

2024-06-26

#DailyBloggingChallenge (320/365)

Implementing ICS was quite easy after finding a functional library on #npmjs.

The difficulty was creating a parsing function that takes the already existing data format and put it into the #ical one. This means the new property duration was introduced using the same schema as provided from the ics library.

2024-06-05

Credential stealer? ✅ Keylogger? ✅ Cryptocurrency stealer? ✅

Phylum uncovers more malicious #npm packages targeting the #Javascript ecosystem.

blog.phylum.io/npm-package-cau

#malware #opensource #bitcoin #cryptocurrency #typescript #software #infosec #cybersecurity #npmjs

2024-04-25

The search bar of npmjs.com is annoyingly broken. You have to press enter twice for it to actually search. It always takes me a moment to remember and I wonder why it's taking so long to load the search results. #npmjs #wtf

2024-04-24

We've uncovered new #malware packages published to #npm that appear to be an evolution on a previous supply chain attack carried out by nation state backed actors ☠

blog.phylum.io/north-korean-st

#npmjs #javascript #supplychainattack #opensource #infosec #reverseengineering #typescript

2024-04-05

It's been ... a while ... since I tried to log into #npmjs.org. So long that now #2fa is required. I don't have an "authenticator" with them and I don't have my "recovery codes". Now I can't login at all. I can't contact them on the support page because I have to "sign in for assistance".

My email history says I enabled it 2 years ago. But my phone from that time is gone.

Have I permanently lost the account? Do I have any other recourse? #javascript #security

Robert Watkinstwasink@aus.social
2024-03-06
Curtis Parfitt-Fordcurtispf@mashed.cloud
2024-02-22

For reasons I can't yet fathom, #npm has specifically blocked me at a WAF level from accessing yarn.npmjs.org. I've not been doing anything other than normal yarn installs, so this is super confusing, and reaching out to npm support has so far been fruitless - with them asking for an npm debug log :(

Does anyone know anyone at #npmjs or #GitHub who might be able to help resolve this? :boostRequest:​

Error Detected

npm has detected malicious activity from someone on your network, and because of that, we are temporarily preventing your network from accessing our services in order to protect npm for the rest of the internet.

Sometimes this means that legitimate use of npm - like yours - is temporarily impacted; we're sorry that this is happening. You can contact our support team at support@npmjs.com - and please include this message and the details (below). This will help you restore our service.

In the meantime, we're working to limit the scope of this problem to only the malicious actors as quickly as possible.
2024-01-17

I wish we could document maintainers for npm packages without those people having direct publish access (i.e., forcing publishes to go through CI/CD)

#npm #npmjs

2024-01-17

#npm had 2.5 million live packages by the end of 2023, downloaded 184+ billion times per month. 5k #malware and 15k #spam packages were found last year. There's a package named 214x the letter "a". There's one almost 6 GB in size!

Remember to always use as less #npmjs dependencies as possible, carefully vet what you're using and to run it in a container (also during dev).

socket.dev/blog/2023-npm-retro

Lorenzo 'kelset' Sciandrakelset@mastodon.online
2024-01-16

24: #npmjs (Node Package Manager) - "The world's largest software registry for JavaScript."

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst