One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance. (opens in new tab)
The npm account ai publishes seven packages. Combined, they install 964 million times per week: Package Weekly downloads Publishers Risk postcss 245,612,332 1 CRITICAL nanoid 206,588,788 1 CRITICAL caniuse-lite 173,435,668 1 CRITICAL browserslist 167,746,012 1 CRITICAL autoprefixer 63,517,741 1 CRITICAL postcss-nested 54,486,292 1 CRITICAL postcss-js 52,771,544 1 CRITICAL That's 50 billion installs per year behind a single set of npm credentials. None of them have npm provenance attestations....
Read the original article