npm
Safeguard articles tagged "npm" — guides, analysis, and best practices for software supply chain and application security.
100 articles
The Twenty-Minute Review to Run Before You Add a Dependency
Adding a dependency takes ten seconds and commits you to trusting a stranger's code on your build machines for as long as the project lives. Six checks, the signals that should stop you, and what this deliberately does not defend against.
Your Internal Package Registry Is the Only Control That Runs Before the Code Does
Most companies run one and treat it as a cache. It is the one place in the build that can refuse a package before an install script executes, which is the only point where prevention is still possible.
ua-parser-js (2021): An npm Account Takeover With Millions of Weekly Downloads
A factual account of the October 2021 ua-parser-js compromise, in which an attacker hijacked the maintainer npm account and published versions containing cryptominer and credential-stealing malware.
event-stream (2018): When a Maintainer Handoff Became a Supply Chain Attack
A factual account of the 2018 event-stream npm compromise, in which a new maintainer added a malicious dependency targeting a specific cryptocurrency wallet, and what it revealed about maintainer-trust risk.
Dependency Confusion (2021): How Public Package Registries Enabled Internal-Name Hijacking
A factual account of Alex Birsan’s 2021 dependency confusion research, which used public npm/PyPI/RubyGems packages matching internal company package names to execute code inside Apple, Microsoft, PayPal, and other major organizations.
Two Supply Chain Compromises, Two Different Failure Modes: TanStack npm and ASUS Live Update
A live npm registry attack against TanStack's trusted GitHub Actions publishing pipeline and a years-old ASUS Live Update client backdoor show two distinct ways software trust gets weaponized.
Two Billion Installs in an Afternoon: The keyv and cacheable npm Worm
On 4 August 2026, one compromised GitHub account seeded a self-propagating npm worm across 444 package names. The packages were caching utilities nobody thinks about — which is why it worked.
Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages
Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.
Nobody Is Exploiting Your Dependencies. They Are Logging Into Them.
keyv, Mastra, Nx, AsyncAPI, jscrambler. Five of 2026's largest supply chain incidents, and not one involved a software vulnerability. The exploited weakness every time was a maintainer account.
npm Classic Tokens Are Gone. The keyv Worm Shows Why That Mattered.
Every npm classic token has been permanently revoked — unrecoverable, unrecreatable. Teams treated it as a chore. Then a worm propagated across 444 packages on exactly that kind of credential.
Bring Your Own Runtime: Why the keyv Payload Downloaded Bun
The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.
npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.
Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.