Safeguard
Tag

npm

Safeguard articles tagged "npm" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Open Source Security

The Twenty-Minute Review to Run Before You Add a Dependency

Adding a dependency takes ten seconds and commits you to trusting a stranger's code on your build machines for as long as the project lives. Six checks, the signals that should stop you, and what this deliberately does not defend against.

Sep 17, 20266 min read
Software Supply Chain Security

Your Internal Package Registry Is the Only Control That Runs Before the Code Does

Most companies run one and treat it as a cache. It is the one place in the build that can refuse a package before an install script executes, which is the only point where prevention is still possible.

Sep 17, 20266 min read
Vulnerability Analysis

ua-parser-js (2021): An npm Account Takeover With Millions of Weekly Downloads

A factual account of the October 2021 ua-parser-js compromise, in which an attacker hijacked the maintainer npm account and published versions containing cryptominer and credential-stealing malware.

Sep 17, 20262 min read
Vulnerability Analysis

event-stream (2018): When a Maintainer Handoff Became a Supply Chain Attack

A factual account of the 2018 event-stream npm compromise, in which a new maintainer added a malicious dependency targeting a specific cryptocurrency wallet, and what it revealed about maintainer-trust risk.

Sep 17, 20262 min read
Vulnerability Analysis

Dependency Confusion (2021): How Public Package Registries Enabled Internal-Name Hijacking

A factual account of Alex Birsan’s 2021 dependency confusion research, which used public npm/PyPI/RubyGems packages matching internal company package names to execute code inside Apple, Microsoft, PayPal, and other major organizations.

Sep 17, 20262 min read
Vulnerability Analysis

Two Supply Chain Compromises, Two Different Failure Modes: TanStack npm and ASUS Live Update

A live npm registry attack against TanStack's trusted GitHub Actions publishing pipeline and a years-old ASUS Live Update client backdoor show two distinct ways software trust gets weaponized.

Sep 16, 20265 min read
Software Supply Chain Security

Two Billion Installs in an Afternoon: The keyv and cacheable npm Worm

On 4 August 2026, one compromised GitHub account seeded a self-propagating npm worm across 444 package names. The packages were caching utilities nobody thinks about — which is why it worked.

Aug 10, 20266 min read
Incident Analysis

Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages

Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.

Aug 9, 20267 min read
Software Supply Chain Security

Nobody Is Exploiting Your Dependencies. They Are Logging Into Them.

keyv, Mastra, Nx, AsyncAPI, jscrambler. Five of 2026's largest supply chain incidents, and not one involved a software vulnerability. The exploited weakness every time was a maintainer account.

Aug 8, 20266 min read
Open Source Security

npm Classic Tokens Are Gone. The keyv Worm Shows Why That Mattered.

Every npm classic token has been permanently revoked — unrecoverable, unrecreatable. Teams treated it as a chore. Then a worm propagated across 444 packages on exactly that kind of credential.

Aug 7, 20266 min read
Threat Intelligence

Bring Your Own Runtime: Why the keyv Payload Downloaded Bun

The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.

Aug 6, 20266 min read
Open Source Security

npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.

Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.

Aug 5, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.