







npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
replacements.fyi - performant, safer npm package alternatives
Find more performant and safer replacements for outdated or unnecessary npm packages.
The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

npm Worm Poisons keyv, cacheable and 400+ Other Packages Across Twelve Organisations
A worm moved one byte-identical credential stealer through more than 400 npm packages in twelve organisations on 4 August 2026, including @ornikar, @deliveroo, @servicetitan, @qlik, Picsart and the keyv and cacheable family. latest still resolves to a poisoned version on most affected names, and the payload installs a dead-man switch that fires when the stolen GitHub token is revoked, so rotating credentials first triggers it.

feat: decentralized registries and mirrors by Aslemammad · Pull Request #2386 · npmx-dev/npmx.dev
This is a pull request for my two months of research on how we can decentralize npm by not breaking any mainstream behavior, so we make it as easy as possible to adopt new paradigms by users withou...
Migrating from GitHub to Codeberg ⚡ Zig Programming Language
Ever since git init ten years ago, Zig has been hosted on GitHub. Unfortunately, when it sold out to Microsoft, the clock started ticking. “Please just give me 5 years before everything goes to shit,” I thought to myself. And here we are, 7 years later, living on borrowed time.

Gabocorp 1997 version archive
Just Fucking Use Go - Blain Smith
Hey, dipshit. You know what compiles in two seconds, deploys as a single binary, and doesn't shit itself when a transitive dependency gets yanked from npm at 3am? Go. The same way HTML has been sitting there since the dawn of the goddamn internet waiting for you to stop overcomplicating the frontend, Go has been sitting there for over a decade waiting for you to stop overcomplicating the backend.
npmx - Package Browser for the npm Registry
a fast, modern browser for the npm registry. Search, browse, and explore packages with a modern interface.

What If npm Ran on AT Protocol?
A thought experiment about what a package registry would look like if built on atproto.
Daniel Roe & Matias Leandro Capeletto - npmx: a fast, modern browser for the npm registry
Updated Auth Scopes Proposal · bluesky-social atproto · Discussion #4013
This is a discussion thread for the July 2025 Auth Scopes proposal
atpkgs
Atpkgs is compatible with the NPM Registry API, so it works with most Node.js package managers.
🙋♂️ so ... for reasons: I would love to know people's frustrations with: - the current npmjs.com - admin user flows on npm web ui (and cli, locally) 🙏