Back to feed
Dev.to
Dev.to
6/18/2026
One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance.

One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance.

Short summary

A single npm account publishes seven packages with 964 million weekly downloads but lacks OIDC provenance attestations, creating supply-chain risk exploited three times in four months. Without provenance, stolen tokens are indistinguishable from legitimate releases affecting ~1 billion annual installs. One-line config fix; audit your project with npx proof-of-commitment.

  • 964M weekly downloads behind one unattested account; three major supply-chain attacks in four months exploited this exact pattern
  • Without provenance, stolen npm tokens look identical to legitimate releases, affecting PostCSS ecosystem and other critical dependencies
  • Fix is one-line config change; scan your project's concentration risk with npx proof-of-commitment

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more