1. X
  2. vlt /vōlt/
Log inSign up
vlt /vōlt/
148 posts
Image
user avatar
vlt /vōlt/
@vltpkg
JavaScript package registries & tooling for teams that move fast.
vlt.io
Joined March 2023
242
Following
1,440
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    vlt /vōlt/
    @vltpkg
    6h
    Last month Drizzle ORM couldn't publish a new release to npm for weeks. Not a bug in their code. Their metadata file crossed npm's 100 MB limit, & the only fix was asking npm support to delete old versions by hand. 🧵
    281
  • user avatar
    vlt /vōlt/
    @vltpkg
    Jul 29
    18 malicious npm packages posed as Alibaba's private internal tooling to slip a cross-platform RAT onto its own developers' machines. The final payload even pulled from Alibaba Cloud to blend in.
    Image
    Malicious npm Packages Deploy Cross-Platform RAT Targeting Alibaba Developers
    From cybersecuritynews.com
    128
  • user avatar
    vlt /vōlt/
    @vltpkg
    Jul 28
    Your AI assistant just suggested an npm package. It looks real, it's well-named, it solves your exact problem. It also never existed until an attacker registered the name & filled it with malware. That's slopsquatting. 🧵
    296
  • user avatar
    vlt /vōlt/
    @vltpkg
    Jul 27
    Developers beware! A fake version of corepack has reared its head again at corepack(dot)org The only spot you'll get the faithful package is global install through npm or vlt ;)
    Image
    itnews.com.au
    Fake Corepack tool site goes quiet after luring devs with malware
    Dropped infostealer and proxy-hijacking software.
    138
  • user avatar
    vlt /vōlt/
    @vltpkg
    Jul 26
    The average node_modules has more contributors than most companies have employees. We just never see their faces.
    320
  • See @vltpkg's full profile

    Sign up
    Log in
Advertisement
Advertisement