NPM Security Concerns

The cluster discusses vulnerabilities and security risks in NPM, such as supply chain attacks, malicious packages, blind trust issues, and historical incidents like left-pad, with debates on NPM's insecurity compared to other package managers.

➡️ Stable 1.1x Security
4,133
Comments
16
Years Active
5
Top Authors
#6164
Topic ID

Activity Over Time

2011
8
2012
8
2013
20
2014
101
2015
58
2016
496
2017
185
2018
550
2019
338
2020
258
2021
409
2022
473
2023
248
2024
212
2025
747
2026
22

Keywords

e.g JS THOSE node.js MIT NPM DNS GP URI ARE npm package packages malicious package managers dependency managers code modules fiasco

Sample Comments

binarymax • Jun 11, 2018 • View on HN

This has nothing to do with NPM. It is a specific package published on NPM. Also, stereotyping and insulting the NPM community is nonconstructive and out of place. Vulnerabilities in packages happen all the time in all kinds of package managers. The lesson here is to not blind-trust any package you come across that might make your job easier.

____tom____ • Sep 29, 2025 • View on HN

What are they doing about the supply chain attacks on npm?

Kiro • Nov 5, 2021 • View on HN

What makes npm more insecure than other packaging systems?

maddyboo • Jun 16, 2021 • View on HN

Why don’t I hear about npm package attack vectors more often? I’d expect it to be super common

_bxg1 • Sep 4, 2019 • View on HN

That's silly. NPM's business relies on its thriving package ecosystem, and ecosystems like it face a very real risk from this problem. It would be in their interest to provide such a service, and it would swiftly become obvious if any funny-business were going on, at which point their reputation would be completely decimated.

caspervonb • May 3, 2018 • View on HN

Like I've been saying, npm is ripe for abuse https://medium.com/p/73fac4bc5068

PunchTornado • May 25, 2017 • View on HN

Aren't these the guys behind the npm fiasco? Wouldn't use them.

ramses0 • Dec 15, 2023 • View on HN

...and yet we worry about `npm` supply chain attacks...

nextaccountic • Mar 24, 2023 • View on HN

Yes, and that's how malware ends up in npm and other package managers

paulgb • May 23, 2017 • View on HN

Blind trust in open source package managers. Look at the damage the removal of left-pad from npm caused, for example, and imagine what could have happened if the author had malicious intent.