Skip to content(if available)orjump to list(if available)

Show HN: Tips to stay safe from NPM supply chain attacks

Show HN: Tips to stay safe from NPM supply chain attacks

2 comments

ยทSeptember 21, 2025

Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices

I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community.

Cheers!

turtleyacht

For reducing external dependencies, it would be nice to somehow know every call made to a package, generating the call tree to replace. That becomes the API of the internal, replacement package.

privatelypublic

Not sure that's possible with JS.