DiscoverChangelog & Friendsnpm under siege (what to do about it)
npm under siege (what to do about it)

npm under siege (what to do about it)

Update: 2025-10-03
Share

Description

Over the past two months, we’ve seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and malware published to packages with billions of weekly downloads. What is going on?! What can we do about it? Our old friend, Feross Aboukhadijeh, joins us to help make sense of it all.


Join the discussion

Changelog++ members save 2 minutes on this episode because they made the ads disappear. Join today!

Sponsors:

  • Depot10x faster builds? Yes please. Build faster. Waste less time. Accelerate Docker image builds, and GitHub Actions workflows. Easily integrate with your existing CI provider and dev workflows to save hours of build time.

Featuring:

Show Notes:


Something missing or broken? PRs welcome!

Comments 
loading
In Channel
The 4 DIMM problem

The 4 DIMM problem

2025-11-2801:50:26

NOT a swarm!

NOT a swarm!

2025-11-2101:41:10

Retreat to attack

Retreat to attack

2025-11-1401:44:16

#define: sheer resistance

#define: sheer resistance

2025-11-0701:42:41

We see dead projects

We see dead projects

2025-10-3101:18:33

Kaizen! Mop-up job

Kaizen! Mop-up job

2025-10-2401:47:36

There will be bleeps

There will be bleeps

2025-10-1701:41:45

Inside Oxide

Inside Oxide

2025-09-2601:10:46

Linux Fest in Texas!

Linux Fest in Texas!

2025-09-1901:19:17

Action absorbs anxiety

Action absorbs anxiety

2025-08-2901:22:54

Oxide is crossing the chasm

Oxide is crossing the chasm

2025-08-1501:39:58

Kaizen! Pipely is LIVE

Kaizen! Pipely is LIVE

2025-08-0801:11:35

SO much to dig into

SO much to dig into

2025-08-0101:23:48

Try harder. Ultrathink!

Try harder. Ultrathink!

2025-07-1801:29:52

loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

npm under siege (what to do about it)

npm under siege (what to do about it)