Citation Bureau
Vol. I
No. 346
XI SEPTEMBER MMXXVI
Software

What is npm?

npm is a package registry for JavaScript software packages, from which files can be served through content delivery networks such as UNPKG. Discussion of the registry has centered on its use as an attack surface and on the scale of software distributed through it.

Release history

  • May 2026 - Nathaniel Whittemore said a chart of npm installs of Codex, installed directly through a terminal interface, showed roughly 100,000 a day in January rising to over a million a day, with recent surges to 1.5 and 1.8 million.
  • Aug 2026 - Dave Bittner said that unlike traditional npm supply chain attacks, the packages do not infect developers who install them; attackers use npm as storage and services such as UNPKG to render malicious pages from legitimate domains, potentially evading security controls.
  • Aug 2026 - Zane Lackey said attackers appeared to choose RSA and Black Hat as the times to start npm worms.
  • Aug 2026 - Zane Lackey said that in January 2027 human interactive confirmation through 2FA will be required before any new publishes can happen.

In the discourse

Attributed discussion of npm.

Best explained

A novel npm supply-chain attack pattern uses npm purely as file storage and Unpkg as a CDN to serve malicious Cloudflare-verification pages from legitimate domains, bypassing developer-install-based detection entirely.

“Unlike traditional npm supply chain attacks, the packages don't infect developers who install them. Instead, attackers use npm as storage and services such as unpackage to render the malicious pages from legitimate domains, potentially helping them evade security controls.”
Dave Bittner · 26 Aug 2026
Company & tool watch

npm is mandating interactive 2FA for all new publishes starting January 2027, a change that will eliminate npm worms but break significant ecosystem automation.

“In January 2027 going to require human you know interactive confirmation through 2FA before any new publishes can happen.”
Zane Lackey · 7 Aug 2026
By the numbers

Codex NPM installs grew roughly 10x from about 100,000 per day in January 2026 to over 1 million per day by May 2026, with recent spikes reaching 1.5 to 1.8 million per day.

“Simon again shared a chart of NPM installs of Codex, which means when Codex was installed directly through a terminal interface. He points out that they were at about 100,000 a day in January and are at over a million a day right now. In fact, in the last couple of days they've surged up to 1.5 and 1.8 million.”
Nathaniel Whittemore · 29 May 2026
Contrarian take

Attackers time npm worm launches to coincide with RSA and Black Hat conferences, exploiting reduced defender attention during major security events.

“I noticed the attackers seem to pick RSA and black hat as the times they wanted to start these npm worms.”
Zane Lackey · 7 Aug 2026
Citation Bureau · reference note, compiled from attributed expert discussion. Last updated 2026-09-11.