RSRushabh Shahindepwarden.hashnode.dev·Sep 7 · 4 min readHow npm typosquatting and dependency confusion attacks work (and how to stop them)In February 2021, security researcher Alex Birsan published a paper describing how he had successfully deployed malicious packages to the internal build systems of Apple, Microsoft, PayPal, Shopify, a00
NPNirdesh pokharelinblog.nirdeshpokhrel.com.np·Sep 3 · 5 min readdigit-to-words-nepali: Converting Numbers to Nepali Words, ProperlyIf you've ever built a billing system, an invoice generator, or a cheque-printing tool for a Nepali audience, you already know the pain: turning 1234 into "एक हजार दुई सय चौँतिस" is not a simple looku00
KRKaustubh Raiinkaustubh-cto.hashnode.dev·Sep 2 · 8 min readThe npm Worm Doesn't Care How Good Your CI IsOn 6 August, Singapore's Cyber Security Agency published an advisory about an active npm supply chain attack involving malicious versions of Keyv and related packages, spread by a worm called Shai-Hul00
4F404 Foundersin404-founders.com·Aug 29 · 5 min readnpm ClickFix: 24 Packages Weaponize MirrorsTwenty-four npm packages published between August 4 and August 24, 2026 do not install malware when you run npm install. Instead, they turn trusted package mirrors into free phishing hosting. CVE: N/00
MSManu Shuklainecorpit.hashnode.dev·Aug 23 · 14 min readCloudflare Gateway now blocks npm and PyPI downloads, but an unparseable version matches nothing, including !=Cloudflare Gateway now blocks npm and PyPI downloads, but an unparseable version matches nothing, including != Summary. Cloudflare shipped package registry security to Gateway on 13 August 2026, letti00
MMMihai Marinescuinfeaturingcode.com·Aug 22 · 28 min readfc-react-dndGlad to announce that I published my first npm library https://www.npmjs.com/package/fc-react-dnd and you can play with it here. How this drag-and-drop library works, traced through one tree Making a 20
ADAlbert Deutouinblog-adeutou.hashnode.dev·Aug 12 · 10 min readnx-safe-suite: A Deep Dive Into Five Production-Grade Next.js PackagesHow each package works, why it is designed the way it is, and what it replaces. This is the second article in a two-part series. The first covers the architecture and the reasoning behind the projec00
ADAlbert Deutouinblog-adeutou.hashnode.dev·Aug 12 · 6 min readI Built Five npm Packages to Solve the Five Problems Every Next.js Backend IgnoresA production-grade toolkit for Next.js backends, and the architectural thinking behind it. After years of building internal tools and SaaS products with Next.js, I kept copying the same five things 00
ASAdeesh Sharmainblog.adeeshsharma.com·Aug 10 · 6 min readReactive Editor: click any element in your live app, let your coding agent fix itEvery time I've asked a coding agent to change something on a screen, the conversation goes the same way. I paste a screenshot. I try to describe which button I mean. The agent guesses, edits a file, 00
MSManu Shuklainecorpit.hashnode.dev·Aug 4 · 17 min read42 poisoned npm versions: the keyv worm containment runbook for 4 August 202642 poisoned npm versions: the keyv worm containment runbook for 4 August 2026 Summary. On 4 August 2026, an attacker took over the GitHub account of the maintainer behind keyv and published malware ac00