npm
npm on Beyond Market Intelligence: a running collection of 2 stories we have gathered and hand-picked because they are worth your time. Every post here touches on npm in some way — the news, the analysis, the deep dives, and the occasional surprise find. Acme AI is the next-generation, AI-powered spreadsheet platform built to replace Excel and redefine how analysts, data scientists, and enterprise teams work with data. New stories are added to this page as we find them, so check back if you want to keep up with what is happening around npm, or subscribe to the RSS feed to get them as soon as they are published. Browse the collection below, or head back to the homepage to see everything Beyond Market Intelligence is covering right now.

VS Code 1.123 Adds Two-Hour Extension Update Delay to Limit Supply Chain Attacks
VS Code 1.123 introduces a critical security enhancement: a two-hour delay for automatic extension updates. This measured approach establishes a revocation window, significantly mitigating potential supply chain attacks by allowing time to verify newly published versions. Trusted publishers—including Microsoft, GitHub, and OpenAI—are exempt from this delay. This move aligns VS Code with similar cooldown mechanisms now standard across package managers like npm and Bun, reflecting an industry-wide focus on security. For further insights into secure API interactions, explore our article on Ky 2.0.

Attacker Bought 30 WordPress Plugins on Flippa and Backdoored All of Them
In a striking security breach, an attacker acquired over 30 WordPress plugins on Flippa for a hefty six-figure sum, embedding a PHP deserialization backdoor in the initial commit. After an eight-month waiting period, the attacker activated the backdoor across 400,000 installations, leveraging Ethereum smart contracts for command and control. This incident highlights a critical vulnerability in WordPress.org, which lacks a mechanism for reviewing plugin ownership transfers—an oversight that platforms like npm and PyPI have addressed in their security protocols.