<?xml version="1.0"?>
<rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:neowin="https://www.neowin.net/">
	<channel>
		<title>Neowin News Feed for: Npm</title>
		<link>https://www.neowin.net/news/tag/npm/</link>
        <atom:link href="https://www.neowin.net/news/rss/npm/" rel="self" type="application/rss+xml" />
		<description>Neowin News Feed for: Npm</description>
		<language>en-us</language>
		<generator>Neowin Ignition News</generator>
		<managingEditor>editor@neowin.net (Managing Editor)</managingEditor>
		<webMaster>developers@neowin.net (Neowin Developers)</webMaster>
		<ttl>5</ttl>
		<image>
			<title>Neowin.net</title>
			<url>https://www.neowin.net/images/pegasus/icon.png</url>
			<link>https://www.neowin.net</link>
		</image>
		        <item>
            <title>JavaScript devs beware: this very popular NPM package has been compromised by attackers</title>
            <link>https://www.neowin.net/news/javascript-devs-beware-this-popular-npm-package-has-been-compromised-by-attackers/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2025/09/1758070589_npm-logo_medium.webp" alt="" /&gt;&lt;/div&gt;An extremely popular NPM package used in many JavaScript projects has been compromised and can wreak havoc on your machine if installed.
 &lt;a href="https://www.neowin.net/news/javascript-devs-beware-this-popular-npm-package-has-been-compromised-by-attackers/"&gt;Read more...&lt;/a&gt;</description>
            <author>David Uzondu</author>
            <pubDate>Tue, 31 Mar 2026 05:24:02 +0000</pubDate>
            <guid>https://www.neowin.net/news/javascript-devs-beware-this-popular-npm-package-has-been-compromised-by-attackers/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2025/09/1758070589_npm-logo_story.webp" width="760" height="428" />
            <neowin:tags>#JavaScript #Axios</neowin:tags>                    </item>
                <item>
            <title>Over 300 npm packages compromised by self-replicating worm</title>
            <link>https://www.neowin.net/news/over-300-npm-packages-compromised-by-self-replicating-worm/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2025/09/1758070589_npm-logo_medium.webp" alt="" /&gt;&lt;/div&gt;A new piece of malware is spreading through the popular tinycolor NPM library and more than 300 other packages, some of which belong to CrowdStrike. &lt;a href="https://www.neowin.net/news/over-300-npm-packages-compromised-by-self-replicating-worm/"&gt;Read more...&lt;/a&gt;</description>
            <author>David Uzondu</author>
            <pubDate>Wed, 17 Sep 2025 01:10:01 +0000</pubDate>
            <guid>https://www.neowin.net/news/over-300-npm-packages-compromised-by-self-replicating-worm/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2025/09/1758070589_npm-logo_story.webp" width="760" height="428" />
            <neowin:tags>#NPM #Worm #JavaScript</neowin:tags>                    </item>
                <item>
            <title>GitHub increases verifiability of npm packages for added security</title>
            <link>https://www.neowin.net/news/github-increases-verifiability-of-npm-packages-for-added-security/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2023/04/1681955930_introducing-npm-package-provenance_medium.jpg" alt="" /&gt;&lt;/div&gt;GitHub now allows npm package developers to link their published packages to their source code to prove that the package was built from the source. This will help build trust and boost security. &lt;a href="https://www.neowin.net/news/github-increases-verifiability-of-npm-packages-for-added-security/"&gt;Read more...&lt;/a&gt;</description>
            <author>Paul Hill</author>
            <pubDate>Thu, 20 Apr 2023 02:12:02 +0000</pubDate>
            <guid>https://www.neowin.net/news/github-increases-verifiability-of-npm-packages-for-added-security/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2023/04/1681955930_introducing-npm-package-provenance_story.jpg" width="760" height="428" />
            <neowin:tags>#GitHub #Provenance</neowin:tags>            <neowin:twitter>@ziks_99</neowin:twitter>        </item>
                <item>
            <title>Package Analysis Project: Google will help detect malicious open source packages</title>
            <link>https://www.neowin.net/news/package-analysis-project-google-will-help-detect-malicious-open-source-packages/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2022/04/1651218816_v6duco_(2)_medium.jpg" alt="" /&gt;&lt;/div&gt;Google has pledged support for OpenSSF&amp;#039;s Package Analysis Project for open source packages uploaded to popular repositories. It has also published the results which paint a rather interesting picture. &lt;a href="https://www.neowin.net/news/package-analysis-project-google-will-help-detect-malicious-open-source-packages/"&gt;Read more...&lt;/a&gt;</description>
            <author>Usama Jawad</author>
            <pubDate>Fri, 29 Apr 2022 07:58:01 +0000</pubDate>
            <guid>https://www.neowin.net/news/package-analysis-project-google-will-help-detect-malicious-open-source-packages/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2022/04/1651218816_v6duco_(2)_story.jpg" width="760" height="428" />
            <neowin:tags>#Google #OSS #OpenSource</neowin:tags>            <neowin:twitter>@UsamaJawad96</neowin:twitter>        </item>
                <item>
            <title>Free eBook: Your First Week With Node.js</title>
            <link>https://www.neowin.net/sponsored/free-ebook-your-first-week-with-nodejs/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2020/10/1601553606_w_sitb125c9_medium.jpg" alt="" /&gt;&lt;/div&gt;This free to download eBook will get you up and running with guides on when to use Node, NPM, Security, as well as connecting with MySQL, MongoDB and more. Claim before offer expires! &lt;a href="https://www.neowin.net/sponsored/free-ebook-your-first-week-with-nodejs/"&gt;Read more...&lt;/a&gt;</description>
            <author>News Staff</author>
            <pubDate>Thu, 01 Oct 2020 20:00:01 +0000</pubDate>
            <guid>https://www.neowin.net/sponsored/free-ebook-your-first-week-with-nodejs/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2020/10/1601553606_w_sitb125c9_story.jpg" width="760" height="428" />
            <neowin:tags>#NodeJS #Free #ebook</neowin:tags>            <neowin:twitter>@aSteveParker</neowin:twitter>        </item>
                <item>
            <title>Microsoft Weekly: More Series X specs, more updates, and more user growth</title>
            <link>https://www.neowin.net/news/microsoft-weekly-more-series-x-specs-more-updates-and-more-user-growth/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2020/03/1584887667_msw-20200322_medium.jpg" alt="" /&gt;&lt;/div&gt;This week we saw the full spec sheet of the Xbox Series X and the features of the controller, Windows 10 finally crossed the one billion active device mark, and much more. Be sure to catch up below. &lt;a href="https://www.neowin.net/news/microsoft-weekly-more-series-x-specs-more-updates-and-more-user-growth/"&gt;Read more...&lt;/a&gt;</description>
            <author>Florin Bodnarescu </author>
            <pubDate>Sun, 22 Mar 2020 14:56:01 +0000</pubDate>
            <guid>https://www.neowin.net/news/microsoft-weekly-more-series-x-specs-more-updates-and-more-user-growth/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2020/03/1584887667_msw-20200322_story.jpg" width="760" height="428" />
            <neowin:tags>#MicrosoftWeekly #Microsoft</neowin:tags>                    </item>
                <item>
            <title>GitHub acquires JavaScript package manager npm</title>
            <link>https://www.neowin.net/news/github-acquires-javascript-package-manager-npm/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2020/03/1584383319_github-npm-blog_medium.jpg" alt="" /&gt;&lt;/div&gt;Microsoft&amp;#039;s GitHub has announced that it&amp;#039;s acquiring npm, a popular package manager for JavaScript applications that&amp;#039;s been available for over 10 years. The value of the transaction wasn&amp;#039;t disclosed. &lt;a href="https://www.neowin.net/news/github-acquires-javascript-package-manager-npm/"&gt;Read more...&lt;/a&gt;</description>
            <author>João Carrasqueira</author>
            <pubDate>Mon, 16 Mar 2020 19:00:01 +0000</pubDate>
            <guid>https://www.neowin.net/news/github-acquires-javascript-package-manager-npm/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2020/03/1584383319_github-npm-blog_story.jpg" width="760" height="428" />
            <neowin:tags>#GitHub #npm</neowin:tags>            <neowin:twitter>@indospot</neowin:twitter>        </item>
                <item>
            <title>Microsoft takes the wraps off TypeScript 3.0, now generally available</title>
            <link>https://www.neowin.net/news/microsoft-takes-the-wraps-off-typescript-30-now-generally-available/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2022/02/1644931722_typescriptimage-1568052628959_medium.jpg" alt="" /&gt;&lt;/div&gt;Almost two years after its last major revision to the programming language, TypeScript 3.0 has been unleashed by Microsoft with editor support available for Visual Studio 2015, 2017, and Code. &lt;a href="https://www.neowin.net/news/microsoft-takes-the-wraps-off-typescript-30-now-generally-available/"&gt;Read more...&lt;/a&gt;</description>
            <author>Boyd Chan</author>
            <pubDate>Tue, 31 Jul 2018 11:38:01 +0000</pubDate>
            <guid>https://www.neowin.net/news/microsoft-takes-the-wraps-off-typescript-30-now-generally-available/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2022/02/1644931722_typescriptimage-1568052628959_story.jpg" width="760" height="428" />
            <neowin:tags>#typescript</neowin:tags>            <neowin:twitter>@therealboydchan</neowin:twitter>        </item>
                <item>
            <title>TypeScript 2.0 now generally available</title>
            <link>https://www.neowin.net/news/typescript-20-now-generally-available/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2022/02/1644931722_typescriptimage-1568052628959_medium.jpg" alt="" /&gt;&lt;/div&gt;Microsoft has announced the availability of the final version of the TypeScript 2.0 programming language, which can be downloaded from NuGet or Node Package Manager. &lt;a href="https://www.neowin.net/news/typescript-20-now-generally-available/"&gt;Read more...&lt;/a&gt;</description>
            <author>Shreyas Gandhe</author>
            <pubDate>Sat, 24 Sep 2016 19:04:01 +0000</pubDate>
            <guid>https://www.neowin.net/news/typescript-20-now-generally-available/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2022/02/1644931722_typescriptimage-1568052628959_story.jpg" width="760" height="428" />
                        <neowin:twitter>@__shreyas</neowin:twitter>        </item>
                <item>
            <title>TypeScript 2.0 nears launch, Release Candidate now available</title>
            <link>https://www.neowin.net/news/typescript-20-nears-launch-release-candidate-now-available/</link>
            <description>&lt;div style="float:left;margin-right:10px;"&gt;&lt;img src="https://cdn.neowin.com/news/images/uploaded/2022/02/1644931722_typescriptimage-1568052628959_medium.jpg" alt="" /&gt;&lt;/div&gt;Microsoft has announced the availability of the release candidate of the TypeScript 2.0 programming language, which can be downloaded from NuGet or Node Package Manager. &lt;a href="https://www.neowin.net/news/typescript-20-nears-launch-release-candidate-now-available/"&gt;Read more...&lt;/a&gt;</description>
            <author>Shreyas Gandhe</author>
            <pubDate>Wed, 31 Aug 2016 19:54:01 +0000</pubDate>
            <guid>https://www.neowin.net/news/typescript-20-nears-launch-release-candidate-now-available/</guid>
            <media:thumbnail url="https://cdn.neowin.com/news/images/uploaded/2022/02/1644931722_typescriptimage-1568052628959_story.jpg" width="760" height="428" />
                        <neowin:twitter>@__shreyas</neowin:twitter>        </item>
        	</channel>
</rss>
