Skip to content
Open Source Beat
Explainers Open Source Projects Developer Tools Programming Languages
DevOps & Infrastructure AI & Machine Learning Security & Privacy Community & Governance Cloud & Databases

#npm

🔒
Security & Privacy

Supply Chain Heist: 'TrapDoor' Steals Dev Credentials

Bad actors are actively targeting developer environments. The 'TrapDoor' campaign's reach across npm, PyPI, and Crates.io is a stark warning.

4 min read 4 days, 17 hours ago
Collage of icons representing code, a network, a robot, and accessibility symbols.
Developer Tools

DEV's Top 7: From Yellow Jackets to AI Hallucinations

DEV’s weekly roundup is here. We've got everything from building containers from scratch to understanding AI's complex failures.

3 min read 1 week, 5 days ago
A person's hands typing on a laptop keyboard with a terminal window open on the screen.
Developer Tools

Node.js Mac Updates: The 'n' Package Method

Forget the endless scrolling and confusing commands. Updating Node.js on your Mac just got a whole lot simpler. This method uses a tool you likely already have access to, turning a chore into a swift maneuver.

4 min read 1 week, 5 days ago
Screenshot of stack-rot tool output showing abandoned and deprecated Node.js packages.
Open Source Projects

[Key Finding] Dependency Scanner 'stack-rot' Tackles Code Rot

Tired of inheriting codebases riddled with dead dependencies? stack-rot is a new tool designed to tell you which packages are truly dead, not just outdated or insecure.

5 min read 2 weeks, 5 days ago
Diagram illustrating the TanStack supply chain attack vector via GitHub Actions.
Security & Privacy

TanStack Attack: 42 Packages Compromised

Six minutes. That’s how long it took a relentless attacker to inject malicious code into 42 npm packages, a brazen display of how vulnerable our trusted open-source supply chains have become. TanStack is out with the nitty-gritty, and it’s not pretty.

5 min read 2 weeks, 5 days ago
Abstract visualization of interconnected code dependencies forming a complex network.
Security & Privacy

The axios Attack: A Supply Chain Wake-Up Call [2026]

A compromised npm package, a stolen maintainer key, and a three-hour window of vulnerability. The [email protected] incident wasn't just a bug; it was a stark reminder that your code's perimeter has expanded.

7 min read 4 weeks, 2 days ago
Comparison chart showing ws package size and dependencies vs. @rabbx/ws
Developer Tools

@rabbx/ws: 2.5KB WebSocket Replacement Arrives

We expected more from our WebSocket libraries. We got bloat instead. Now, there's @rabbx/ws, a featherweight contender that might just save us all from node_modules hell.

6 min read 1 month ago
Screenshot of npm package page for gni-compression, highlighting installation command and description.
Community & Governance

Domain-Adaptive LLM Compression Hits npm: 12x Savings Realized

Is your LLM context window bleeding your budget? A new open-source tool, gni-compression, promises to slash token costs with remarkable efficiency. We break down the data.

5 min read 1 month ago
Node.js logo with version number 24.13.1 prominently displayed.
Programming Languages

Node.js 24.13.1: Stability & Dependencies Update

Node.js 24.13.1 LTS is here, a minor release packed with incremental improvements. It's not a revolution, but it fortifies the foundation for developers worldwide.

4 min read 1 month, 1 week ago

Categories

Explainers Open Source Projects Developer Tools Programming Languages DevOps & Infrastructure AI & Machine Learning Security & Privacy Community & Governance
Open Source Beat

Community-driven. Code-first.

More

  • RSS Feed
  • Sitemap
  • About
  • Editorial Process
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Open Source Beat Open Source Fintech Dose Crypto & DeFi Chip Beat Semiconductors AdTech Beat Ad Technology Supply Chain Beat Logistics

© 2026 Open Source Beat. All rights reserved.

🏠Home 🔍Search 🔖Saved 📂Categories
Privacy & cookies

We use a privacy-respecting analytics tool to count page views — no personal profiles, no ad tracking, no third-party cookies. Accept to help us understand which stories matter to readers.

Details