npm should-i-install: Malicious npm packages - Anatomy, Detection gaps and AI's role

No ratings

Presented at SnowFROC 2026 by

The software supply chain is under constant attack, and nowhere is this clearer than the JavaScript ecosystem. In 2023, over 5,000 malicious npm packages were removed; by mid-2024 that number exceeded half a million. Recent compromises like NX Singularity, Chalk/Debug, and the Shai-Hulud worm show that attackers are no longer uploading random malware but hijacking trusted packages with millions of downloads.