Skip to content
DevTools Feed
New Releases DevOps & Platform Eng Open Source Cloud & Infrastructure
AI Dev Tools Databases & Backend Frontend & Web Engineering Culture

#npm-security

Leaked source map file from Anthropic's Claude Code npm package exposing full codebase
New Releases

Anthropic's Claude Code Leaks Entire Source—Via NPM Debug File, Not a Hack

At 4:23 AM ET, an intern spots a monster debug file in Claude Code's npm package. By breakfast, Anthropic's codebase is mirrored worldwide. No hackers. Just a forgotten .npmignore line.

4 min read 3 days, 7 hours ago
attach-guard blocking compromised axios npm install in Claude Code terminal
New Releases

I Installed a Compromised npm Package with Claude Code — Then Built This Plugin to Stop It

Picture this: Your AI coding buddy fires off 'npm install axios' — and it's laced with malware. One dev built attach-guard to slam the brakes, turning Claude Code into a supply chain fortress.

4 min read 3 days, 8 hours ago
Fake Slack workspace branded for phishing attack on axios maintainer
Open Source

North Korean Hackers Fake a Company to Pwn Axios Maintainer – RAT in 100M Downloads

Picture this: a Teams call with 'colleagues' from a polished fake company. One 'update' click later, North Koreans control your machine and poison a library with 100 million downloads. Open source just got conned.

4 min read 3 days, 15 hours ago
Timeline diagram of axios@1.14.1 supply chain attack from account takeover to RAT deployment
New Releases

Axios 1.14.1: The NPM Hijack That Stole Your SSH Keys in Seconds

Ever wonder if that quick 'npm install axios@latest' just handed your AWS keys to a stranger? On March 31, 2026, it did—for 40 million weekly users.

3 min read 4 days, 6 hours ago
Nicholas Zakas on Changelog podcast critiquing npm security flaws
DevOps & Platform Eng

ESLint Creator Nicholas Zakas: GitHub's npm Fixes Are Mere Table Stakes

Nicholas Zakas, ESLint's creator, isn't mincing words: GitHub's npm security moves are 'table stakes,' not solutions. One big attack could shatter JavaScript's package empire.

3 min read 4 days, 7 hours ago
DevTools Feed

Ship faster. Build smarter.

Categories

  • New Releases
  • DevOps & Platform Eng
  • Open Source
  • Cloud & Infrastructure
  • AI Dev Tools
  • Databases & Backend
  • Frontend & Web
  • Engineering Culture

More

  • RSS Feed
  • Sitemap
  • About
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking Open Source Beat Open Source Fintech Dose Crypto & DeFi

© 2026 DevTools Feed. All rights reserved.

📬

Stay in the loop

The week's most important stories from DevTools Feed, delivered once a week.

No spam. Unsubscribe any time.

You clearly love Developer Tools news — get it in your inbox

🏠 Home 🔍 Search 🔖 Saved 📂 Categories