Dev.to
6/18/2026

One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance.
Short summary
A single npm account publishes seven packages with 964 million weekly downloads but lacks OIDC provenance attestations, creating supply-chain risk exploited three times in four months. Without provenance, stolen tokens are indistinguishable from legitimate releases affecting ~1 billion annual installs. One-line config fix; audit your project with npx proof-of-commitment.
- •964M weekly downloads behind one unattested account; three major supply-chain attacks in four months exploited this exact pattern
- •Without provenance, stolen npm tokens look identical to legitimate releases, affecting PostCSS ecosystem and other critical dependencies
- •Fix is one-line config change; scan your project's concentration risk with npx proof-of-commitment
Generated with AI, which can make mistakes.
Is this a good recommendation for you?


