Skip to content
TrackPodcasts
technologyOct 3, 20251:35:20pending

npm under siege (what to do about it) (Friends)

About this episode

Over the past two months, we’ve seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and malware published to packages with billions of weekly downloads. What is going on?! What can we do about it? Our old friend, Feross Aboukhadijeh, joins us to help make sense of it all.

Get every episode summarized

Each time The Changelog: Software Development, Open Source publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

npm under siege (what to do about it) (Friends)

The Changelog: Software Development, Open Source

0:00
1:35:20

More episodes

More from The Changelog: Software Development, Open Source

View all episodes →