The npm worm playbook for a small team
Three self-propagating npm campaigns in twelve months: the TanStack compromise in May, ChainDrop through keyv in August, 400 plus packages backdoored from one stolen token. You cannot audit your way out of this. Here is the set of controls that actually stops a worm at the door, with the config for each.
8 min readRead more →