I did a lot of thinking about the npm supply chain attacks over my break. I wrote up my thoughts, along with some proposed solutions, in my latest post:
humanwhocodes.com/blog/2026/01…
How GitHub could secure npm - Human Who Codes
Why doesn't npm detect compromised packages the way credit card companies detect fraud?Human Who Codes

Seedy!
in reply to Jayson Smith • • •Khronos
in reply to Seedy! • • •