← The FeatureThe FeatureHow-To
Three Defenses Against npm Supply-Chain Attacks
After watching, a developer can name and enable at least two concrete, low-effort defenses -- lockfile-enforced installs and a release-age cooldown -- that would have stopped most real 2026 npm supply-chain attacks.
A real 2026 attack on the TanStack npm packages -- which even reached OpenAI's own systems -- shows how fast these compromises spread. Three concrete, low-effort defenses any development team can enable this week.
Sources
- Our response to the TanStack npm supply chain attack — OpenAI
- Defending Against NPM Supply Chain Attacks: A Practical Guide — Armorcode (Karan Bansal)
- npm Supply Chain Security in 2026: What Your Package Manager Does (and Doesn't) Protect You From — Mondoo
- The npm Threat Landscape: Attack Surface and Mitigations — Palo Alto Networks Unit 42
The Feature is a daily educational video series, editorially independent of the Signal newsletter.Browse all Features → · Sign up for the Signal →