cd/entity/npm· home entities npm
grep -l @npm /news/*.json | wc -l → 299

npm

mentions 299 type Organization page 12/15 feed RSS

// recent coverage 299 mentions

16:38
2026-06-14
github.com
ai-tools

Structured Subagents for Claude Code

WastedCode released TrueCast, a CLI and plugin system that installs portable expert personas—such as product manager, architect, and security reviewer—into Claude Code sessions. The tool provides vers…

07:58
2026-06-14
dev.to
artificial-intelligence

Why your AI agent ignores the rules you wrote

A developer explains why AI agents often ignore explicit rules, using a React Native project example where a rule against using 'pnpm add' for native packages was broken, causing a build failure. The …

09:22
2026-06-13
socket.dev
developer-tools

Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformati

Socket's Threat Research team identified 23 new malicious PyPI packages in the Mini Shai-Hulud, Miasma, and Hades supply chain attacks, expanding the campaign to 471 artifacts across npm and PyPI. The…

07:21
2026-06-13
developer.microsoft.com
developer-tools

Agent just scaffolded a project from 2020

An AI agent scaffolded a project using an outdated 2020 version because npx resolved to an old package version without engine constraints, due to npm's version resolution prioritizing engine compatibi…

17:54
2026-06-11
devblogs.microsoft.com
developer-tools

Your agent just scaffolded a project from 2020

AI agents using npx without specifying a version can inadvertently scaffold projects from outdated templates due to npm's engine compatibility resolution, which prioritizes older versions without engi…

14:00
2026-06-09
arize.com
ai-agents

How to detect credential theft in AI agent harness traces

In May 2026, two supply-chain attacks targeted AI coding tools including Claude Code and Cursor, with one malicious VS Code extension stealing npm, AWS, GitHub, and SSH credentials from 6,000 develope…

10:00
2026-06-09
safedep.io
ai-tools

Inside the Miasma Software Supply Chain Attack Toolkit

The Miasma software supply chain attack toolkit has been released as open source across multiple GitHub repositories, likely through compromised developer accounts. The toolkit enables attackers to ex…

00:00
2026-06-07
jackfranklin.co.uk
ai-tools

ai-review: reviewing AI code before it lands

Developer Jack Franklin launched ai-review, an open-source tool that lets terminal-based AI coding agents present plans and diffs in a browser for line-by-line review. The tool bridges the gap between…

17:36
2026-06-06
dev.to
ai-tools

Rust Was Crashing. Go Fixed It. Copilot Showed Me Why

A developer built Delay Mirror, a supply chain security gateway for package managers that blocks downloads of packages published within the last three days, after malicious code was pushed into npm pa…

← prev page 12 / 15 next →
// co-occurs with top 8 entities
// topics top 6 topics