>_ Posts

Blog

Thoughts on development, engineering, and product.

1 post
  • 01|

    Two attacks in four days, a package with 15,000 weekly downloads, and npm v12 arriving to try to stop the bleeding

    Injective SDK and Jscrambler were compromised in July 2026, fitting the same pattern that already hit Axios, Red Hat, and node-ipc this year. npm v12, expected this month, promises to end automatic install scripts — but experts say that doesn't fix the real problem.