Benchmarks of JavaScript Package Managers
Was not aware of that: pnpm regularly updates this benchmarks that compares npm, yarn and pnpm
weeklyfoo #18 / 2024-02-05Benchmarks of JavaScript Package Managers
Was not aware of that: pnpm regularly updates this benchmarks that compares npm, yarn and pnpm
weeklyfoo #18 / 2024-02-05Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
weeklyfoo #69 / 2025-01-27Leaner npm packument (metadata) contents
Modern JavaScript library starter
How to publish a package with TypeScript, testing, GitHub Actions, and auto-publish to NPM
weeklyfoo #18 / 2024-02-05Nightmares on npm: How Two Malicious Packages Facilitate Data Theft and Destruction
Our threat research team breaks down two malicious npm packages designed to exploit developer trust, steal your data, and destroy data on your machine.
weeklyfoo #54 / 2024-10-14npm in Review: A 2023 Retrospective on Growth, Security, and Quirky Facts
npm malware
NPM registry prank leaves developers unable to unpublish packages
The Great npm Garbage Patch
The package that broke NPM (accidentally)
The story behing the <everything> npm package that stressed npm
weeklyfoo #15 / 2024-01-14Why Does 'is-number' Package Have 59M Weekly Downloads?