2025-07-26 UTC
#
[tantek] on a more serious note, since have a number of folks who use (depend on) npm for their personal sites here, I figured these were worth sharing ASAP: https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack and https://www.bleepingcomputer.com/news/security/hackers-breach-toptal-github-account-publish-malicious-npm-packages/
