Safeguard
Tag

npm-security

Safeguard articles tagged "npm-security" — guides, analysis, and best practices for software supply chain and application security.

172 articles

Security

How Secure Is js-cookie? A Practical Security Guide

js-cookie is a tiny, popular cookie helper, but a 2026 attribute-injection flaw shows why the library needs the same scrutiny as any other dependency. Here is what to watch.

Jun 19, 20267 min read
Open Source

pdf-lib npm: A Security Review and Safe Usage Guide

pdf-lib is a popular pure-JavaScript library for creating and editing PDFs, with no known direct vulnerabilities but an inactive maintenance status worth planning around.

Jun 18, 20266 min read
Security

JavaScript Security Vulnerabilities: The Ones That Actually Bite

JavaScript security vulnerabilities cluster around a few patterns: XSS, prototype pollution, ReDoS, and dependency risk. Here is how each works and how to catch it.

Jun 18, 20266 min read
AI Security

Slopsquatting: When AI Hallucinates Package Names

LLMs invent plausible package names; attackers register them and wait. How slopsquatting works, why hallucinations repeat predictably, and the gates that stop it.

Jun 14, 20266 min read
Open Source

Choosing an npm Vulnerability Scanner That Catches Real Threats

npm audit is only the starting point. Here is how an npm vulnerability scanner should handle transitive risk, reachability, install scripts, and lockfile integrity.

Jun 12, 20266 min read
AppSec

PrismJS: Vulnerability History and Hardening Your Syntax Highlighting

The npm prismjs package has patched ReDoS, plugin XSS, and a DOM clobbering flaw over the years. Here is the full history and how to run a syntax highlighter safely.

Jun 12, 20266 min read
Open Source Security

How Snyk detects malicious and typosquatted open-source p...

How Snyk's research team detects malicious and typosquatted open-source packages — from name-similarity heuristics to install-script analysis and source-code provenance checks.

Jun 9, 20266 min read
Open Source

react-native-flash-message: A Security Guide

The react-native-flash-message package is a popular but no-longer-maintained notification library. Here is what its inactive status means for your app's security.

Jun 8, 20266 min read
Open Source

fast-xml-parser on npm: Security Review and Safe Usage

fast-xml-parser is one of the most-downloaded XML parsers on npm. Here is its security history, the CVEs that mattered, and how to use it safely.

Jun 5, 20265 min read
Open Source

superagent npm: Security Review and Safe HTTP Requests

SuperAgent is a mature HTTP client for Node.js, but old versions carry prototype pollution and information-exposure flaws. Here is a practical security review.

Jun 5, 20266 min read
Threat Intelligence

What Is Open Source Malware

Open source malware is code deliberately planted in packages to attack the systems that install it. Learn how it spreads, real incidents, and how it differs from CVEs.

Jun 3, 20267 min read
Open Source

Is the ioredis npm Package Secure? A Practical Review

The ioredis npm package is a solid, well-maintained Redis client, but most real risk lives in how you configure the connection rather than in the library code itself.

Jun 2, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

npm-security (Page 7) — Safeguard Blog