Has anyone else noticed malicious npm packages targeting AI coding tools? My scanner found 21 in 24 hours with 4 undocumented attack vectors

Temporal: The 9-year journey to fix time in JavaScript

The three pillars of JavaScript bloat

axios 1.14.1 and 0.30.4 on npm are compromised - dependency injection via stolen maintainer account

We Added a Console Notice to Internationalizationext – and Why We Removed It

Debounce is not enough: handling stale responses with AbortController and retries

Supply Chain Attack on Axios

Vite 8.0 Is Out

Basic physics engine in about 100 lines of pure JavaScript

Prerelease of Ky 2.0

bonsai - a safe expression language for JS that does 30M ops/sec with zero dependencies

Oxlint & Oxfmt Compatibility Overview

TypeScript 6.0 RC

Announcing TypeScript 6.0

Show HN: Zerobox – Sandbox any command with file, network, credential controls

Zerobox: Lightweight, cross-platform process sandboxing. Sandbox any command with file, network, and credential controls.

The Cost of 'Lightweight' Frameworks: From Tauri to Native Rust

No AI in Node.js Core

We're building a better rich text editing toolkit

MikroORM 7: Unchained

@wcstack/state – reactive state in plain HTML with no build step

I built a game because I can no longer tell the difference between JS frameworks and prescription drugs.

Next.js Across Platforms: Adapters, OpenNext, and Our Commitments

JavaScript's date parser is out of control and needs to be stopped

Minimum Release Age is an Underrated Supply Chain Defense

I built the fastest way to render rich text on canvas 5x faster than SVG foreignObject

Zero Config (and free) WebSockets

Edge.js: Run Node apps inside a WebAssembly sandbox

How to Write Time-Based Security Policies in SafeDep vet

Drizzle Joins PlanetScale

More →