tag: npm
articles: 2 · beats: 1
latest: July 14, 2026
---
npm
2 Crashtech articles on npm, filed under Development Best Practices, published in July 2026. Every piece is full-text HTML with sources, structured data and an authored FAQ.
All 2 sit in the Development Best Practices beat. Development Best Practices
A Misconfigured GitHub Action Backdoored Packages With 3M Weekly Downloads
A pull_request_target flaw in AsyncAPI's CI let attackers steal a token and trojan 4 npm packages — 3M+ weekly downloads — with credential-stealing code.
npm's Biggest Security Overhaul in 16 Years Is Here — Attackers Are Already Adapting
npm v12 blocks install scripts, Git dependencies, and remote sources by default. Researchers say attackers are already routing around it.
Questions we answer about npm
- What GitHub Actions vulnerability did the attacker exploit?
- How many npm packages were compromised, and how widely were they used?
- What did the malicious payload actually do?
- Why wasn't this vulnerability fixed before the attack happened?
- Does blocking npm install scripts stop this kind of attack?
- What does npm v12 actually change by default?
- Why is npm making this change now, in July 2026?
- Does npm v12 stop supply-chain attacks entirely?
- What happens to CI/CD pipelines that rely on install scripts?
- How are attackers already adapting to npm v12?
Covered alongside
Frequently asked questions
What does Crashtech publish about npm?
2 articles tagged npm, the most recent published July 14, 2026. All 2 sit in the Development Best Practices beat. Each carries numbered sources, an authored FAQ and full structured data.
What questions about npm does Crashtech answer directly?
10 questions have a dedicated answer page under this tag, including “What GitHub Actions vulnerability did the attacker exploit?”. Each answer is authored prose from the article it belongs to, not a generated summary.
Can AI assistants read Crashtech's npm coverage?
Yes. Crashtech serves full static HTML to every crawler, allows all major AI user agents in robots.txt, and publishes an llms.txt manifest plus a full-text corpus, so assistants can retrieve and cite these articles directly.