Npm
Supply Chain Attacks Keep Hitting npm. Here Is What AWS Says Actually Helps
AWS wrote a long post on supply chain security after Shai-Hulud and the other npm attacks this year. We read it so you don't have to. Here is what's actually worth doing.
npm v12 Will Stop Running Install Scripts by Default: What It Means and How to Prepare
npm v12 comes in July 2026 and it changes how npm install works. Install scripts, git dependencies and remote tarballs will be blocked by default. Here is what changes, why, and what you should do now.
323 npm Packages Poisoned in 22 Minutes: Inside the AntV Supply Chain Attack
On May 19, 2026, a compromised npm account pushed malicious versions of 323 packages across Alibaba's AntV ecosystem. The payload reads GitHub Actions runner memory to extract masked secrets in plaintext. Here is what happened, how it works, and what to do.