DEV Community

One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance. (opens in new tab)

Discussed on DEV

The npm account ai publishes seven packages. Combined, they install 964 million times per week: Package Weekly downloads Publishers Risk postcss 245,612,332 1 CRITICAL nanoid 206,588,788 1 CRITICAL caniuse-lite 173,435,668 1 CRITICAL browserslist 167,746,012 1 CRITICAL autoprefixer 63,517,741 1 CRITICAL postcss-nested 54,486,292 1 CRITICAL postcss-js 52,771,544 1 CRITICAL That's 50 billion installs per year behind a single set of npm credentials. None of them have npm provenance attestations....

Read the original article
Sign in to keep reading the full article.

Keyboard Shortcuts

Navigation

Next / previous post
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Discover
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help