A Deep Dive into npm Supply Chain Attacks and Defense (opens in new tab)
On May 19, 2026, the charting library antv was attacked, and the latest version was embedded with malicious code. On May 13, the popular TanStack series repo in the frontend community was also attacked. On April 1, axios, which has a hundred million downloads weekly, was similarly attacked, and a malicious version was released. It seems that news about supply chain attacks appears every month or even every week, and the targets are not limited to npm; Python’s PyPI, .NET’s NuGet, and even Doc...
Read the original article