NPM Security Concerns

The cluster discusses vulnerabilities and security risks in NPM, such as supply chain attacks, malicious packages, blind trust issues, and historical incidents like left-pad, with debates on NPM's insecurity compared to other package managers.

➡️ Stable 1.1x Security
4,133
Comments
16
Years Active
5
Top Authors
#6164
Topic ID

Activity Over Time

2011
8
2012
8
2013
20
2014
101
2015
58
2016
496
2017
185
2018
550
2019
338
2020
258
2021
409
2022
473
2023
248
2024
212
2025
747
2026
22

Keywords

e.g JS THOSE node.js MIT NPM DNS GP URI ARE npm package packages malicious package managers dependency managers code modules fiasco

Sample Comments

binarymax Jun 11, 2018 View on HN

This has nothing to do with NPM. It is a specific package published on NPM. Also, stereotyping and insulting the NPM community is nonconstructive and out of place. Vulnerabilities in packages happen all the time in all kinds of package managers. The lesson here is to not blind-trust any package you come across that might make your job easier.

____tom____ Sep 29, 2025 View on HN

What are they doing about the supply chain attacks on npm?

Kiro Nov 5, 2021 View on HN

What makes npm more insecure than other packaging systems?

maddyboo Jun 16, 2021 View on HN

Why don’t I hear about npm package attack vectors more often? I’d expect it to be super common

_bxg1 Sep 4, 2019 View on HN

That's silly. NPM's business relies on its thriving package ecosystem, and ecosystems like it face a very real risk from this problem. It would be in their interest to provide such a service, and it would swiftly become obvious if any funny-business were going on, at which point their reputation would be completely decimated.

caspervonb May 3, 2018 View on HN

Like I've been saying, npm is ripe for abuse https://medium.com/p/73fac4bc5068

PunchTornado May 25, 2017 View on HN

Aren't these the guys behind the npm fiasco? Wouldn't use them.

ramses0 Dec 15, 2023 View on HN

...and yet we worry about `npm` supply chain attacks...

nextaccountic Mar 24, 2023 View on HN

Yes, and that's how malware ends up in npm and other package managers

paulgb May 23, 2017 View on HN

Blind trust in open source package managers. Look at the damage the removal of left-pad from npm caused, for example, and imagine what could have happened if the author had malicious intent.