Skip to content

[BUG] <title>Subsequent malware attacks and security issues in the npm supply chain #8574

@seniorit

Description

@seniorit

Is there an existing issue for this?

  • I have searched the existing issues

This issue exists in the latest npm version

  • I am using the latest npm

Current Behavior

Subsequent malware attacks and security issues in the npm supply chain

Recently, the npm ecosystem has suffered several supply chain attacks shortly after its launch, and this has been widely reported in the Spanish-speaking community by people like midudev 🧐👍😄

Apart from removing the carets, we have no other option, but it doesn't solve the underlying problem. I created my own implementation for my private projects, which isn't the best solution, but it works for me for now. However, I would like to know how we can collaborate or contribute to making the npm platform, which is the benchmark in the nodejs ecosystem, more secure for all of us who use it and the community in general.

Finally, I would appreciate it if you could indicate if you have already contacted an issue regarding this specific topic. 😎

Environment

  • npm:11.5.2
  • Node.js: v22.19.0
  • OS Name: Fedora Linux 42
  • System Model Name:Lenovo IdeaPad Core i7-13620H

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bugthing that needs fixingNeeds Triageneeds review for next steps

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions