The package manager for JavaScript Problems? Visit npmjs.com/support or github.com/npm/feedback

we just shipped a number of security-focused improvements to npm including: - naming access tokens - enforcing 2FA in your npm orgs - improved auditing for 2FA adoption in orgs - selecting teams when adding new org members read more in our Changelog ⬇️ github.blog/changelog/2022-0…
2
24
53
Demo Days is live! Join us to talk complex workflows, managing multiple projects in a single monorepo, securing dependencies and more with the @npmjs CLI.
3
4
6
In case you missed it, the @npmjs CLI has been making big strides lately. Join us this Friday on Demo Days and we’ll deep dive into Workspaces, Overrides and more! linkedin.com/feed/update/urn…
1
7
21
npm retweeted
📣 please note: we won't be holding open rfc calls for the next two weeks.
2
1
10
an update on recent security incidents across the registry as well as a look into our ongoing investments in maintaining the security of the registry (including 2FA requirements) ⬇️ github.blog/2021-11-15-githu…
6
63
131
this morning we detected multiple versions of the “coa” package published with malicious code due to a compromised account of a maintainer. we quickly removed the compromised versions and have published an advisory: github.com/advisories/GHSA-7…. npm itself was not compromised. [1/3]
7
109
146
to protect your accounts and packages from similar attacks, we highly recommend enabling 2FA on your npm account: docs.npmjs.com/configuring-t…. [3/3]
10
6
28
following ongoing investigations, we identified in real time multiple versions of the “rc” package containing identical malware to the “coa” package. malicious versions of “rc” were immediately removed from the registry and we have published an advisory: github.com/advisories/GHSA-g…
4
26
44