Skip to content

πŸ“° npm

15 Recent Node.js Features that Replace Popular npm Packages

Over the years, Node.js developers have relied on countless npm packages to fill gaps in the platform.

weeklyfoo #106 / 2025-10-13
nodejsnpm

Benchmarks of JavaScript Package Managers

Was not aware of that: pnpm regularly updates this benchmarks that compares npm, yarn and pnpm

weeklyfoo #18 / 2024-02-05
benchmarkpnpmyarnnpm

cleaning house in nx monorepo, how i removed 120 unused deps safely

Short version, I ran Knip across our Nx repo, took the unused list as a hint, deleted candidates, built, tested, booted apps, and put a few back when they were secretly used.

weeklyfoo #106 / 2025-10-13
dependenciesnpm

How to keep package.json under control

Val Town is a React application with a ton of dependencies. It’s complicated, and we have to deal with dependency upgrades all the time.

weeklyfoo #102 / 2025-09-15
dependenciesjavascriptnpm

Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar

Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.

weeklyfoo #69 / 2025-01-27
securitynpm

Leaner npm packument (metadata) contents

And by doing that reducing the size of packuments.

weeklyfoo #42 / 2024-07-22
npm

Mastering NPX

A Cheatsheet for npm and Node.js Power Users

weeklyfoo #105 / 2025-10-06
npxcheatsheetnpmnodejs

Modern JavaScript library starter

How to publish a package with TypeScript, testing, GitHub Actions, and auto-publish to NPM

weeklyfoo #18 / 2024-02-05
npmpackagestarter

Nightmares on npm: How Two Malicious Packages Facilitate Data Theft and Destruction

Our threat research team breaks down two malicious npm packages designed to exploit developer trust, steal your data, and destroy data on your machine.

weeklyfoo #54 / 2024-10-14
securitynpm

npm Adopts OIDC for Trusted Publishing in CI/CD Workflows

npm now supports Trusted Publishing with OIDC, enabling secure package publishing directly from CI/CD workflows without relying on long-lived tokens.

weeklyfoo #99 / 2025-08-25
npmoidcsecurity

npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack

npm author Qix’s account was compromised, with malicious versions of popular packages like chalk-template, color-convert, and strip-ansi published.

weeklyfoo #102 / 2025-09-15
securitynpm

npm in Review: A 2023 Retrospective on Growth, Security, and Quirky Facts

A look back, and some funny suprises.

weeklyfoo #16 / 2024-01-22
npm2023

npm malware

Get informed about malicious npm packages in realtime

weeklyfoo #17 / 2024-01-28
npmmalware

NPM registry prank leaves developers unable to unpublish packages

everything fetches everything

weeklyfoo #14 / 2024-01-07
npm

npm trusted publishing with OIDC is generally available

As of today, npm trusted publishing with OpenID Connect (OIDC) is now generally available.

weeklyfoo #97 / 2025-08-11
npm

Our plan for a more secure npm supply chain

Addressing a surge in package registry attacks, GitHub is strengthening npm’s security with stricter authentication, granular tokens, and enhanced trusted publishing to restore trust in the open source ecosystem.

weeklyfoo #104 / 2025-09-29
securitynpmsupply-chain

The Great npm Garbage Patch

Thousands of spam npm packages are polluting the system.

weeklyfoo #46 / 2024-08-19
npmspam

The package that broke NPM (accidentally)

The story behing the &lteverything> npm package that stressed npm

weeklyfoo #15 / 2024-01-14
npm

The Risks of NPM

In this post, I’m talking about the Qix incident.

weeklyfoo #104 / 2025-09-29
npmsecurity

We shouldn’t have needed lockfiles

About the non sense of lockfiles

weeklyfoo #97 / 2025-08-11
lockfilesnpm

Which npm package has the largest version number?

I spent way too much time on this

weeklyfoo #103 / 2025-09-22
investigationsnpm

Why Does 'is-number' Package Have 59M Weekly Downloads?

Just saying: chain of dependencies!

weeklyfoo #22 / 2024-03-04
npm