<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 skin-theme-clientpref-day vector-sticky-header-enabled" lang="de" dir="ltr"><head>
<meta charset="UTF-8">
<title>Npm (Software)</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://de.wikipedia.org/wiki/Npm_(Software)"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link href="./_mw_/ext.gadget.citeRef.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.defaultPlainlinks.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonHide.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonLayout.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonStyle.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiDarkmode.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiResponsive.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.specialSearch.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Npm_Software rootpage-Npm_Software skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">npm (Software)</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="de" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="de" dir="ltr"><table class="float-right infobox toccolours toptextcells" style="border-spacing:5px; font-size:90%; text-align:left; width:21em;">
<tbody><tr>
<th colspan="2" class="hintergrundfarbe6" style="font-size:105%; text-align:center;">npm
<p class="mw-empty-elt">
</p>
</th></tr>
<tr>
<td colspan="2" class="notheme" style="text-align:center; background-color:#f8f9fa;"><span typeof="mw:File"></span>
</td></tr>
<tr>
<th colspan="2" class="hintergrundfarbe5" style="font-size:105%; text-align:center;">Basisdaten
<p class="mw-empty-elt">
</p>
</th></tr>
<tr>
<td><b><a href="Softwareentwickler" title="Softwareentwickler">Entwickler</a></b>
</td>
<td>Isaac Z. Schlueter / npm, Inc.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</td></tr>
<tr>
<td><b>Erscheinungsjahr</b>
</td>
<td>12. Januar 2010<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</td></tr>
<tr>
<td><b>Aktuelle <a href="Version_(Software)" title="Version (Software)">Version</a></b>
</td>
<td><span class="wikidata-content">11.7.0<sup id="cite_ref-_33dec1c21154a6a8_3-0" class="reference"><a href="#cite_note-_33dec1c21154a6a8-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup></span> <br> (<span class="wikidata-content">9. Dezember 2025</span>)
</td></tr>
<tr>
<td><b><a href="Betriebssystem" title="Betriebssystem">Betriebssystem</a></b>
</td>
<td><span class="wikidata-content"><a href="Plattformunabh%C3%A4ngigkeit" title="Plattformunabhängigkeit">Plattformunabhängig</a></span>
</td></tr>
<tr>
<td><b><a href="Programmiersprache" title="Programmiersprache">Programmiersprache</a></b>
</td>
<td><a href="JavaScript" title="JavaScript">JavaScript</a>
</td></tr>
<tr>
<td><b>Kategorie</b>
</td>
<td><a href="Paketverwaltung" title="Paketverwaltung">Paketverwaltung</a>
</td></tr>
<tr>
<td><b>Lizenz</b>
</td>
<td><a href="Artistic_License" title="Artistic License">Artistic License</a> 2.0
</td></tr>
<tr>
<td><b><a href="Lokalisierung_(Softwareentwicklung)" title="Lokalisierung (Softwareentwicklung)">deutschsprachig</a></b>
</td>
<td>nein
</td></tr>
<tr>
<td class="hintergrundfarbe5" colspan="2" style="text-align:center;"><a rel="nofollow" class="external text" href="https://www.npmjs.com/">www.npmjs.com</a>
</td></tr></tbody></table>
<p><b>npm</b> (ehemals <i>Node Package Manager</i>) ist ein <a href="Paketmanager" class="mw-redirect" title="Paketmanager">Paketmanager</a> für die <a href="JavaScript" title="JavaScript">JavaScript</a>-Laufzeitumgebung <a href="Node.js" title="Node.js">Node.js</a>. <i>npm</i> wurde 2010 von Isaac Schlueter als Mitarbeiter des kalifornischen <a href="Cloud_Computing" title="Cloud Computing">Cloud</a>-Plattform-Anbieters Joyent programmiert. 2014 gründete er die „npm, inc.“<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p><p>Unter dem Namen <i>npm Registry</i> bzw. <i>npm Open Source</i> wird ein <a href="Repository" title="Repository">Repository</a> betrieben, über das 350.000 Pakete (Stand 13. Januar 2017<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>) unter einer <a href="Freie_Software" title="Freie Software">freien Lizenz</a> bereitgestellt werden.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Für private Pakete (also nicht <a href="Open_Source" title="Open Source">Open Source</a>) wird eine kommerzielle Version angeboten.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>Hinter der Entwicklung und dem Betrieb des Repository steht die Firma <i>npm, Inc.</i> mit Sitz in <a href="Oakland" title="Oakland">Oakland</a>, <a href="Kalifornien" title="Kalifornien">Kalifornien</a>,<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> die seit 2020 <a href="GitHub" title="GitHub">GitHub</a> gehört<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> und somit zum <a href="Microsoft" title="Microsoft">Microsoft</a>-Konzern.
</p>
<div class="mw-heading mw-heading2"><h2 id="Sicherheit">Sicherheit</h2></div>
<p>Wie jedes Repository ist die <i>npm Registry</i> dafür anfällig, dass Pakete mit <a href="Schadcode" class="mw-redirect" title="Schadcode">Schadcode</a> eingestellt werden. Sobald solche Pakete via <a href="Kopplung_(Softwareentwicklung)" title="Kopplung (Softwareentwicklung)">Abhängigkeiten</a> in einem Softwareprojekt verwendet werden, können verschiedenste Angriffe ausgeführt werden. In der Vergangenheit wurden Attacken via <a href="Typosquatting" title="Typosquatting">Typosquatting</a><sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> und <a href="Social_Engineering_(Sicherheit)" title="Social Engineering (Sicherheit)">Social Engineering</a><sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> bekannt. Im Jahr 2021 präsentierte ein Sicherheitsforscher einen weiteren <a href="Angriffsvektor" title="Angriffsvektor">Angriffsvektor</a>, indem er schadhafte Pakete auf npm.com veröffentlichte und dabei den Paketnamen so wählte, dass er dem von Softwarefirmen intern verwendeten Paketnamen entspricht. Bei einer Fehlkonfiguration wurde in weiterer Folge das schadhafte Paket heruntergeladen und dessen Code ausgeführt.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Probleme">Probleme</h2></div>
<p>Wegen einer Meinungsverschiedenheit in Bezug auf den Namen eines Pakets und der Reaktion der <i>npm Registry</i> darauf löschte im März 2016 ein Entwickler sämtliche seiner Pakete aus dem Repository, unter anderem auch <code>left-pad</code>. Daraufhin konnte eine Vielzahl von Paketen wie Babel (ein <a href="JSX_(JavaScript)" title="JSX (JavaScript)">JSX</a>-nach-JavaScript-Compiler) und <a href="React" title="React">React</a> nicht mehr <a href="Compiler" title="Compiler">kompiliert</a> werden, weil diese das Paket benötigen.<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> Dies löste eine Debatte über den Einsatz von vielen Mikro-Modulen in der JavaScript-Community und die Abhängigkeit von einem kommerziell geführten Repository aus.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> Des Weiteren wurden im Repository Maßnahmen gesetzt, um in Zukunft solche Probleme zu vermeiden: Veröffentlichte Versionen von Paketen können nur innerhalb von 24 Stunden selbstständig oder durch Kontaktieren des Supports zurückgezogen werden.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p><p>Im Januar 2018 wurde versehentlich ein Benutzer blockiert und damit auch der Download seiner 102 Pakete. Aus diesem Grund konnte eine Vielzahl von bekannten JavaScript-Projekten nicht installiert/gebaut werden.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</p><p>Am 4. November 2021 wurde bekannt, dass mittels eines kompromittierten <a href="Maintainer" title="Maintainer">Maintainer</a>-Zugangs, Schadcode über die Repositories <code>coa</code><sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup> (<i>Command Line Parser</i>) und <code>rc</code><sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup> (<i>Configuration Loader</i>) ausgeliefert wurde.<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p><p>Im Januar 2022 fügte der Entwickler des Pakets <code>colors</code> bewusst eine <a href="Endlosschleife_(Programmierung)" title="Endlosschleife (Programmierung)">Endlosschleife</a> ein und machte somit dieses Paket, welches seinerseits als Abhängigkeit in circa 20.000 Paketen verwendet wird, unbrauchbar.<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup>
</p><p>Im April 2022 wurde ein weiterer <a href="Angriffsvektor" title="Angriffsvektor">Angriffsvektor</a> publik – „Package Planting“: npm ermöglichte es, Maintainer zu Paketen hinzuzufügen, ohne dass diese zustimmen mussten. Ein Angreifer konnte sich <a href="Typosquatting" title="Typosquatting">Typosquatting</a> bedienen und ein für ein populäres Paket (wie beispielsweise <a href="Express.js" title="Express.js">Express.js</a>) ein ähnlich geschriebenes Paket mit Schadcode veröffentlichen. Durch das Hinzufügen der ursprünglichen Maintainer konnte dem schadhaften Paket Vertrauenswürdigkeit verliehen werden und die unwissenden Maintainer des richtigen Paketes konnten <a href="Diffamierung" title="Diffamierung">diffamiert</a> werden.<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p><p>Im September 2025 wurde in Hunderten populären Pakete wie beispielsweise <code>@ctrl/tinycolor</code> Schadcode mit dem Namen »TruffleHog« platziert, welcher auf den befallenen Systemen nach Zugangstoken und API-Credentials sucht und exfiltriert. Als Einfallstor diente ein NPM-Authentifizierungs-Token.<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup> Im Oktober 2025 setzte NPM Maßnahmen um: die Gültigkeit der Authentifizierungs-Token wird herabgesetzt, <a href="Passkeys" class="mw-redirect" title="Passkeys">Passkeys</a> wird als <a href="Zwei-Faktor-Authentisierung" title="Zwei-Faktor-Authentisierung">2FA</a> eingeführt, <a href="Time-based_one-time_password" title="Time-based one-time password">Time-based one-time password</a> als 2FA wird abgekündigt.<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Name">Name</h2></div>
<p>Die Bezeichnung <i>Node Package Manager</i> geht auf die <a href="Readme" title="Readme">Readme</a>-Datei des Projekts zurück.<sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup> Im Dezember 2014 wurde die Bezeichnung allerdings entfernt.<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup> Auf der <a href="Frequently_Asked_Questions" title="Frequently Asked Questions">FAQ</a>-Seite des Projekts wurde zwischen August 2011 und November 2015 <i>npm</i> als "<a href="Rekursives_Akronym" title="Rekursives Akronym">rekursives</a>" <a href="Backronym" title="Backronym">Backronym</a> für „npm is not an acronym“ („npm ist kein <a href="Akronym" title="Akronym">Akronym</a>“) definiert, welches tatsächlich jedoch nicht rekursiv ist.<sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup> Seit September 2014 werden Community-basiert mögliche Erklärungen für <i>npm</i> im <a href="GitHub" title="GitHub">GitHub</a>-Projekt <code>npm-expansions</code> gesammelt und auf der Webseite angezeigt.<sup id="cite_ref-35" class="reference"><a href="#cite_note-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Siehe_auch">Siehe auch</h2></div>
<ul><li><a href="Bower_(Software)" title="Bower (Software)">Bower</a> – Paketverwaltung für clientseitige JavaScript-Pakete</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Einzelnachweise">Einzelnachweise</h2></div>
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><a href="#cite_ref-1">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.npmjs.com/about">About</a></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><a href="#cite_ref-2">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://github.com/npm/npm/releases?after=v0.1.1"><i>Erste Versionen von npm.</i></a> In: <i>GitHub.</i><span class="Abrufdatum"> Abgerufen am 5. Januar 2019</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Erste+Versionen+von+npm&rft.description=Erste+Versionen+von+npm&rft.identifier=&rft.date="> </span></span>
</li>
<li id="cite_note-_33dec1c21154a6a8-3"><span class="mw-cite-backlink"><a href="#cite_ref-_33dec1c21154a6a8_3-0">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/npm/cli/releases/tag/v11.7.0"><cite style="font-style:italic"><span lang="en">Release 11.7.0</span></cite>.</a> 9. Dezember 2025 (abgerufen am 10. Dezember 2025).</span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><a href="#cite_ref-4">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://increment.com/development/interview-with-isaac-z-schlueter-ceo-of-npm/">increment.com: Glenn Fleischmann: Interview with Isaac Z. Schlueter, CEO of npm</a></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><a href="#cite_ref-5">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.linux.com/news/event/Nodejs/2016/state-union-npm"><i>State of the Union: npm.</i></a> In: <i>Linux.com | The source for Linux information.</i><span class="Abrufdatum"> Abgerufen am 16. Januar 2017</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=State+of+the+Union%3A+npm&rft.description=State+of+the+Union%3A+npm&rft.identifier=https%3A%2F%2Fwww.linux.com%2Fnews%2Fevent%2FNodejs%2F2016%2Fstate-union-npm"> </span></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><a href="#cite_ref-6">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20160325211926/https://www.npmjs.com/npm/open-source"><i>npm Open Source.</i></a> In: <i>npmjs.com.</i> Archiviert vom <style data-mw-deduplicate="TemplateStyles:r250917974">
/* start https://de.wikipedia.org/ */
.mw-parser-output .dewiki-iconexternal>a{background-position:center right!important;background-repeat:no-repeat!important}body.skin-minerva .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/OOjs_UI_icon_external-link-ltr-progressive.svg")!important;background-size:10px!important;padding-right:13px!important}body.skin-timeless .mw-parser-output .dewiki-iconexternal>a,body.skin-monobook .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/MediaWiki_external_link_icon.svg")!important;padding-right:13px!important}body.skin-vector .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/Link.ernal-small-ltr-progressive.svg")!important;background-size:0.857em!important;padding-right:1em!important}
/* end https://de.wikipedia.org/ */
</style><span class="dewiki-iconexternal"><a class="external text" href="https://redirecter.toolforge.org/?url=https%3A%2F%2Fwww.npmjs.com%2Fnpm%2Fopen-source">Original</a></span> (nicht mehr online verfügbar) am <span style="white-space:nowrap;">25. März 2016</span><span>;</span><span class="Abrufdatum"> abgerufen am 24. März 2016</span> (englisch).</span> <small class="archiv-bot"><span class="wp_boppel noviewer" aria-hidden="true" role="presentation"><span typeof="mw:File"><span title="i"></span></span></span> <b>Info:</b> Der Archivlink wurde automatisch eingesetzt und noch nicht geprüft. Bitte prüfe Original- und Archivlink gemäß Anleitung und entferne dann diesen Hinweis.</small><span style="display:none"><a rel="nofollow" class="external text" href="http://IABotmemento.invalid/https://www.npmjs.com/npm/open-source">@1</a></span><span style="display:none"><a rel="nofollow" class="external text" href="https://www.npmjs.com/npm/open-source">@2</a></span><span style="display:none">Vorlage:Webachiv/IABot/www.npmjs.com</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=npm+Open+Source&rft.description=npm+Open+Source&rft.identifier=https%3A%2F%2Fweb.archive.org%2Fweb%2F20160325211926%2Fhttps%3A%2F%2Fwww.npmjs.com%2Fnpm%2Fopen-source&rft.source=https://www.npmjs.com/npm/open-source&rft.language=en"> </span></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><a href="#cite_ref-7">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.npmjs.com/npm/private-packages"><i>npm Private Packages.</i></a> In: <i>npmjs.com.</i><span class="Abrufdatum"> Abgerufen am 24. März 2016</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=npm+Private+Packages&rft.description=npm+Private+Packages&rft.identifier=https%3A%2F%2Fwww.npmjs.com%2Fnpm%2Fprivate-packages&rft.language=en"> </span></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><a href="#cite_ref-8">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.npmjs.com/about"><i>About npm.</i></a> In: <i>npmjs.com.</i><span class="Abrufdatum"> Abgerufen am 24. März 2016</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=About+npm&rft.description=About+npm&rft.identifier=https%3A%2F%2Fwww.npmjs.com%2Fabout&rft.language=en"> </span></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><a href="#cite_ref-9">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://github.blog/2020-03-16-npm-is-joining-github/"><i>npm is joining GitHub.</i></a> In: <i>github.blog.</i><span class="Abrufdatum"> Abgerufen am 16. März 2020</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=npm+is+joining+GitHub&rft.description=npm+is+joining+GitHub&rft.identifier=https%3A%2F%2Fgithub.blog%2F2020-03-16-npm-is-joining-github%2F&rft.language=en"> </span> <span class="cite"><a rel="nofollow" class="external text" href="https://www.microsoft.com/de-de/techwiese/news/npm-wird-teil-von-github.aspx"><i>npm wird Teil von GitHub.</i></a> In: <i>microsoft.com.</i><span class="Abrufdatum"> Abgerufen am 20. März 2020</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=npm+wird+Teil+von+GitHub&rft.description=npm+wird+Teil+von+GitHub&rft.identifier=https%3A%2F%2Fwww.microsoft.com%2Fde-de%2Ftechwiese%2Fnews%2Fnpm-wird-teil-von-github.aspx"> </span></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><a href="#cite_ref-10">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry"><i>`crossenv` malware on the npm registry.</i></a> In: <i>The npm Blog.</i> 2. August 2017,<span class="Abrufdatum"> abgerufen am 12. Januar 2018</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=%60crossenv%60+malware+on+the+npm+registry&rft.description=%60crossenv%60+malware+on+the+npm+registry&rft.identifier=https%3A%2F%2Fblog.npmjs.org%2Fpost%2F163723642530%2Fcrossenv-malware-on-the-npm-registry&rft.date=2017-08-02&rft.language=en"> </span></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><a href="#cite_ref-11">↑</a></span> <span class="reference-text">David Gilbertson: <cite class="lang" lang="en" dir="auto" style="font-style:italic">I’m harvesting credit card numbers and passwords from your site. Here’s how.</cite> In: <cite class="lang" lang="en" dir="auto" style="font-style:italic">Hacker Noon</cite>. 6. Januar 2018 (englisch, <a rel="nofollow" class="external text" href="https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5">hackernoon.com</a> [abgerufen am 12. Januar 2018]).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rfr_id=info:sid/de.wikipedia.org:Npm+%28Software%29&rft.atitle=I%E2%80%99m+harvesting+credit+card+numbers+and+passwords+from+your+site.+Here%E2%80%99s+how.&rft.au=David+Gilbertson&rft.btitle=Hacker+Noon&rft.date=2018-01-06&rft.genre=book" style="display:none"> </span></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><a href="#cite_ref-12">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.heise.de/news/Sicherheitsforscher-bricht-ueber-Open-Source-Repositories-bei-PayPal-Co-ein-5051635.html"><i>Sicherheitsforscher bricht über Open-Source-Repositories bei PayPal & Co. ein.</i></a> In: <i>heise online.</i> 10. Februar 2021,<span class="Abrufdatum"> abgerufen am 11. Februar 2021</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Sicherheitsforscher+bricht+%C3%BCber+Open-Source-Repositories+bei+PayPal+%26+Co.+ein&rft.description=Sicherheitsforscher+bricht+%C3%BCber+Open-Source-Repositories+bei+PayPal+%26+Co.+ein&rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnews%2FSicherheitsforscher-bricht-ueber-Open-Source-Repositories-bei-PayPal-Co-ein-5051635.html&rft.date=2021-02-10&rft.language=de"> </span></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><a href="#cite_ref-13">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.heise.de/newsticker/meldung/JavaScript-Paket-aus-NPM-entfernt-Node-Babel-und-Co-scheiterten-beim-Build-3148796.html"><i>JavaScript-Paket aus NPM entfernt: Node, Babel und Co. scheiterten beim Build.</i></a> In: <i>heise online.</i> 23. März 2016,<span class="Abrufdatum"> abgerufen am 25. März 2016</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=JavaScript-Paket+aus+NPM+entfernt%3A+Node%2C+Babel+und+Co.+scheiterten+beim+Build&rft.description=JavaScript-Paket+aus+NPM+entfernt%3A+Node%2C+Babel+und+Co.+scheiterten+beim+Build&rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnewsticker%2Fmeldung%2FJavaScript-Paket-aus-NPM-entfernt-Node-Babel-und-Co-scheiterten-beim-Build-3148796.html&rft.date=2016-03-23"> </span></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><a href="#cite_ref-14">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20210327093144/https://kodfabrik.com/journal/i-ve-just-liberated-my-modules"><i>I've Just Liberated My Modules - Azer Koçulu's Journal.</i></a> 27. März 2021, archiviert vom <span class="dewiki-iconexternal"><a class="external text" href="https://redirecter.toolforge.org/?url=https%3A%2F%2Fkodfabrik.com%2Fjournal%2Fi-ve-just-liberated-my-modules">Original</a></span> (nicht mehr online verfügbar) am <span style="white-space:nowrap;">27. März 2021</span><span>;</span><span class="Abrufdatum"> abgerufen am 20. November 2023</span>.</span> <small class="archiv-bot"><span class="wp_boppel noviewer" aria-hidden="true" role="presentation"><span typeof="mw:File"><span title="i"></span></span></span> <b>Info:</b> Der Archivlink wurde automatisch eingesetzt und noch nicht geprüft. Bitte prüfe Original- und Archivlink gemäß Anleitung und entferne dann diesen Hinweis.</small><span style="display:none"><a rel="nofollow" class="external text" href="http://IABotmemento.invalid/https://kodfabrik.com/journal/i-ve-just-liberated-my-modules">@1</a></span><span style="display:none"><a rel="nofollow" class="external text" href="https://kodfabrik.com/journal/i-ve-just-liberated-my-modules">@2</a></span><span style="display:none">Vorlage:Webachiv/IABot/kodfabrik.com</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=I%27ve+Just+Liberated+My+Modules+-+Azer+Ko%C3%A7ulu%27s+Journal&rft.description=I%27ve+Just+Liberated+My+Modules+-+Azer+Ko%C3%A7ulu%27s+Journal&rft.identifier=https%3A%2F%2Fweb.archive.org%2Fweb%2F20210327093144%2Fhttps%3A%2F%2Fkodfabrik.com%2Fjournal%2Fi-ve-just-liberated-my-modules&rft.date=2021-03-27&rft.source=https://kodfabrik.com/journal/i-ve-just-liberated-my-modules"> </span></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><a href="#cite_ref-15">↑</a></span> <span class="reference-text"><span class="cite">Mike Roberts: <a rel="nofollow" class="external text" href="https://web.archive.org/web/20201108093459/https://medium.com/@mproberts/a-discussion-about-the-breaking-of-the-internet-3d4d2a83aa4d"><i>A discussion about the breaking of the Internet.</i></a> In: <i>Medium.</i> 23. März 2016, archiviert vom <span class="dewiki-iconexternal"><a class="external text" href="https://redirecter.toolforge.org/?url=https%3A%2F%2Fmedium.com%2F%40mproberts%2Fa-discussion-about-the-breaking-of-the-internet-3d4d2a83aa4d">Original</a></span> (nicht mehr online verfügbar) am <span style="white-space:nowrap;">8. November 2020</span><span>;</span><span class="Abrufdatum"> abgerufen am 25. März 2016</span> (englisch).</span> <small class="archiv-bot"><span class="wp_boppel noviewer" aria-hidden="true" role="presentation"><span typeof="mw:File"><span title="i"></span></span></span> <b>Info:</b> Der Archivlink wurde automatisch eingesetzt und noch nicht geprüft. Bitte prüfe Original- und Archivlink gemäß Anleitung und entferne dann diesen Hinweis.</small><span style="display:none"><a rel="nofollow" class="external text" href="http://IABotmemento.invalid/https://medium.com/@mproberts/a-discussion-about-the-breaking-of-the-internet-3d4d2a83aa4d">@1</a></span><span style="display:none"><a rel="nofollow" class="external text" href="https://medium.com/@mproberts/a-discussion-about-the-breaking-of-the-internet-3d4d2a83aa4d">@2</a></span><span style="display:none">Vorlage:Webachiv/IABot/medium.com</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=A+discussion+about+the+breaking+of+the+Internet&rft.description=A+discussion+about+the+breaking+of+the+Internet&rft.identifier=https%3A%2F%2Fweb.archive.org%2Fweb%2F20201108093459%2Fhttps%3A%2F%2Fmedium.com%2F%40mproberts%2Fa-discussion-about-the-breaking-of-the-internet-3d4d2a83aa4d&rft.creator=Mike+Roberts&rft.date=2016-03-23&rft.source=https://medium.com/@mproberts/a-discussion-about-the-breaking-of-the-internet-3d4d2a83aa4d&rft.language=en"> </span></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><a href="#cite_ref-16">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://news.ycombinator.com/item?id=11348798"><i>NPM and Left-Pad: Have We Forgotten How to Program?</i></a> In: <i>Hacker News.</i><span class="Abrufdatum"> Abgerufen am 25. März 2016</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=NPM+and+Left-Pad%3A+Have+We+Forgotten+How+to+Program%3F&rft.description=NPM+and+Left-Pad%3A+Have+We+Forgotten+How+to+Program%3F&rft.identifier=https%3A%2F%2Fnews.ycombinator.com%2Fitem%3Fid%3D11348798"> </span></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><a href="#cite_ref-17">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://blog.npmjs.org/post/141577284765/kik-left-pad-and-npm"><i>kik, left-pad, and npm.</i></a> In: <i>blog.npmjs.org.</i> 23. März 2016,<span class="Abrufdatum"> abgerufen am 25. März 2016</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=kik%2C+left-pad%2C+and+npm&rft.description=kik%2C+left-pad%2C+and+npm&rft.identifier=https%3A%2F%2Fblog.npmjs.org%2Fpost%2F141577284765%2Fkik-left-pad-and-npm&rft.date=2016-03-23&rft.language=en"> </span></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><a href="#cite_ref-18">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://blog.npmjs.org/post/141905368000/changes-to-npms-unpublish-policy"><i>changes to npm’s unpublish policy.</i></a> In: <i>blog.npmjs.org.</i> 29. März 2016,<span class="Abrufdatum"> abgerufen am 30. März 2016</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=changes+to+npm%E2%80%99s+unpublish+policy&rft.description=changes+to+npm%E2%80%99s+unpublish+policy&rft.identifier=https%3A%2F%2Fblog.npmjs.org%2Fpost%2F141905368000%2Fchanges-to-npms-unpublish-policy&rft.date=2016-03-29&rft.language=en"> </span></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><a href="#cite_ref-19">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.heise.de/newsticker/meldung/JavaScript-npm-aendert-Unpublish-Policy-fuer-Pakete-3155904.html"><i>JavaScript: npm ändert Unpublish Policy für Pakete.</i></a> In: <i>heise online.</i> 30. März 2016,<span class="Abrufdatum"> abgerufen am 30. März 2016</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=JavaScript%3A+npm+%C3%A4ndert+Unpublish+Policy+f%C3%BCr+Pakete&rft.description=JavaScript%3A+npm+%C3%A4ndert+Unpublish+Policy+f%C3%BCr+Pakete&rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnewsticker%2Fmeldung%2FJavaScript-npm-aendert-Unpublish-Policy-fuer-Pakete-3155904.html&rft.date=2016-03-30"> </span></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><a href="#cite_ref-20">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://blog.npmjs.org/post/169582189317/incident-report-npm-inc-operations-incident-of"><i>Incident report: npm, Inc. operations incident of January 6, 2018.</i></a> 11. Januar 2018,<span class="Abrufdatum"> abgerufen am 12. Januar 2018</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Incident+report%3A+npm%2C+Inc.+operations+incident+of+January+6%2C+2018&rft.description=Incident+report%3A+npm%2C+Inc.+operations+incident+of+January+6%2C+2018&rft.identifier=https%3A%2F%2Fblog.npmjs.org%2Fpost%2F169582189317%2Fincident-report-npm-inc-operations-incident-of&rft.date=2018-01-11&rft.language=en"> </span></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><a href="#cite_ref-21">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external free" href="https://github.com/advisories/GHSA-73qr-pfmq-6rp8">https://github.com/advisories/GHSA-73qr-pfmq-6rp8</a></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><a href="#cite_ref-22">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external free" href="https://github.com/advisories/GHSA-g2q5-5433-rhrf">https://github.com/advisories/GHSA-g2q5-5433-rhrf</a></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><a href="#cite_ref-23">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external free" href="https://twitter.com/npmjs/status/1456310581846163457">https://twitter.com/npmjs/status/1456310581846163457</a></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><a href="#cite_ref-24">↑</a></span> <span class="reference-text"><span class="cite">heise online: <a rel="nofollow" class="external text" href="https://www.heise.de/news/Paketmanager-npm-Entwickler-macht-eigene-Packages-unbrauchbar-6322366.html"><i>Paketmanager npm: Entwickler macht eigene Packages unbrauchbar.</i></a> 11. Januar 2022,<span class="Abrufdatum"> abgerufen am 27. April 2022</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Paketmanager+npm%3A+Entwickler+macht+eigene+Packages+unbrauchbar&rft.description=Paketmanager+npm%3A+Entwickler+macht+eigene+Packages+unbrauchbar&rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnews%2FPaketmanager-npm-Entwickler-macht-eigene-Packages-unbrauchbar-6322366.html&rft.creator=heise+online&rft.date=2022-01-11&rft.language=de"> </span></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><a href="#cite_ref-25">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.npmjs.com/package/colors?activeTab=dependents"><i>colors.</i></a> In: <i>npmjs.com.</i><span class="Abrufdatum"> Abgerufen am 27. April 2022</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=colors&rft.description=colors&rft.identifier=https%3A%2F%2Fwww.npmjs.com%2Fpackage%2Fcolors%3FactiveTab%3Ddependents&rft.language=en"> </span></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><a href="#cite_ref-26">↑</a></span> <span class="reference-text"><span class="cite">heise online: <a rel="nofollow" class="external text" href="https://www.heise.de/news/Npm-Schwachstelle-Vertrauen-ist-gut-Kontrolle-ist-besser-7066873.html"><i>Npm-Schwachstelle „Package Planting“: Vertrauen ist gut, Kontrolle ist besser.</i></a> 27. April 2022,<span class="Abrufdatum"> abgerufen am 27. April 2022</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Npm-Schwachstelle+%E2%80%9EPackage+Planting%E2%80%9C%3A+Vertrauen+ist+gut%2C+Kontrolle+ist+besser&rft.description=Npm-Schwachstelle+%E2%80%9EPackage+Planting%E2%80%9C%3A+Vertrauen+ist+gut%2C+Kontrolle+ist+besser&rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnews%2FNpm-Schwachstelle-Vertrauen-ist-gut-Kontrolle-ist-besser-7066873.html&rft.creator=heise+online&rft.date=2022-04-27&rft.language=de"> </span></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><a href="#cite_ref-27">↑</a></span> <span class="reference-text"><span class="cite">heise online: <a rel="nofollow" class="external text" href="https://www.heise.de/news/Neuer-NPM-Grossangriff-Selbst-vermehrende-Malware-infiziert-Dutzende-Pakete-10651111.html"><i>Neuer npm-Großangriff: Hunderte Pakete mit selbst-vermehrender Malware infiziert.</i></a> 16. September 2025,<span class="Abrufdatum"> abgerufen am 16. Oktober 2025</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Neuer+npm-Gro%C3%9Fangriff%3A+Hunderte+Pakete+mit+selbst-vermehrender+Malware+infiziert&rft.description=Neuer+npm-Gro%C3%9Fangriff%3A+Hunderte+Pakete+mit+selbst-vermehrender+Malware+infiziert&rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnews%2FNeuer-NPM-Grossangriff-Selbst-vermehrende-Malware-infiziert-Dutzende-Pakete-10651111.html&rft.creator=heise+online&rft.date=2025-09-16&rft.language=de"> </span></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><a href="#cite_ref-28">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://socket.dev/blog/ongoing-supply-chain-attack-targets-crowdstrike-npm-packages"><i>Updated and Ongoing Supply Chain Attack Targets CrowdStrike ...</i></a> In: <i>socket.dev.</i><span class="Abrufdatum"> Abgerufen am 16. Oktober 2025</span> (amerikanisches Englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Updated+and+Ongoing+Supply+Chain+Attack+Targets+CrowdStrike+...&rft.description=Updated+and+Ongoing+Supply+Chain+Attack+Targets+CrowdStrike+...&rft.identifier=https%3A%2F%2Fsocket.dev%2Fblog%2Fongoing-supply-chain-attack-targets-crowdstrike-npm-packages&rft.language=en-US"> </span></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><a href="#cite_ref-29">↑</a></span> <span class="reference-text"><span class="cite">Scott Cooper: <a rel="nofollow" class="external text" href="https://sigh.dev/posts/ctrl-tinycolor-post-mortem/"><i>@ctrl/tinycolor Supply Chain Attack Post-mortem.</i></a> In: <i>sigh.dev.</i> 16. September 2025,<span class="Abrufdatum"> abgerufen am 16. Oktober 2025</span> (amerikanisches Englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=%40ctrl%2Ftinycolor+Supply+Chain+Attack+Post-mortem&rft.description=%40ctrl%2Ftinycolor+Supply+Chain+Attack+Post-mortem&rft.identifier=https%3A%2F%2Fsigh.dev%2Fposts%2Fctrl-tinycolor-post-mortem%2F&rft.creator=Scott+Cooper&rft.date=2025-09-16&rft.language=en-US"> </span></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><a href="#cite_ref-30">↑</a></span> <span class="reference-text"><span class="cite">heise online: <a rel="nofollow" class="external text" href="https://www.heise.de/news/Nach-Grossangriff-Paketmanager-NPM-schneidet-alte-Sicherheits-Zoepfe-ab-10767942.html"><i>Nach Großangriff: Paketmanager NPM schneidet alte Sicherheits-Zöpfe ab.</i></a> 16. Oktober 2025,<span class="Abrufdatum"> abgerufen am 16. Oktober 2025</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Nach+Gro%C3%9Fangriff%3A+Paketmanager+NPM+schneidet+alte+Sicherheits-Z%C3%B6pfe+ab&rft.description=Nach+Gro%C3%9Fangriff%3A+Paketmanager+NPM+schneidet+alte+Sicherheits-Z%C3%B6pfe+ab&rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnews%2FNach-Grossangriff-Paketmanager-NPM-schneidet-alte-Sicherheits-Zoepfe-ab-10767942.html&rft.creator=heise+online&rft.date=2025-10-16&rft.language=de"> </span></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><a href="#cite_ref-31">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://github.com/npm/npm/commit/4626dfa73b7847e9c42c1f799935f8242794d020"><i>Initial drop. Ugly, sketchy, and not even yet quite a „work in progr…“ · npm/npm@4626dfa.</i></a> In: <i>GitHub.</i> 29. September 2009,<span class="Abrufdatum"> abgerufen am 7. April 2016</span>: „npm – The Node Package Manager“</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Initial+drop.+Ugly%2C+sketchy%2C+and+not+even+yet+quite+a+%E2%80%9Ework+in+progr%E2%80%A6%E2%80%9C+%C2%B7+npm%2Fnpm%404626dfa&rft.description=Initial+drop.+Ugly%2C+sketchy%2C+and+not+even+yet+quite+a+%E2%80%9Ework+in+progr%E2%80%A6%E2%80%9C+%C2%B7+npm%2Fnpm%404626dfa&rft.identifier=https%3A%2F%2Fgithub.com%2Fnpm%2Fnpm%2Fcommit%2F4626dfa73b7847e9c42c1f799935f8242794d020&rft.date=2009-09-29"> </span></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><a href="#cite_ref-32">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://github.com/npm/npm/commit/cbb890eeacc0501ba1b8c6955f1c829c8af9f486"><i>npm is a nice JavaScript package manager · npm/npm@cbb890e.</i></a> In: <i>GitHub.</i> 12. Dezember 2014,<span class="Abrufdatum"> abgerufen am 7. April 2016</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=npm+is+a+nice+JavaScript+package+manager+%C2%B7+npm%2Fnpm%40cbb890e&rft.description=npm+is+a+nice+JavaScript+package+manager+%C2%B7+npm%2Fnpm%40cbb890e&rft.identifier=https%3A%2F%2Fgithub.com%2Fnpm%2Fnpm%2Fcommit%2Fcbb890eeacc0501ba1b8c6955f1c829c8af9f486&rft.date=2014-12-12"> </span></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><a href="#cite_ref-33">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://github.com/npm/npm/commit/9c0b24898b782e2bf43073bb1d836bbe67b339b3"><i>Question about Capitalization · npm/npm@9c0b248.</i></a> In: <i>GitHub.</i> 6. August 2011,<span class="Abrufdatum"> abgerufen am 7. April 2016</span>: „Contrary to the belief of many, „npm“ is not in fact an abbreviation for „Node Package Manager“. It is a recursive bacronymic abbreviation for „npm is not an acronym“.“</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=Question+about+Capitalization+%C2%B7+npm%2Fnpm%409c0b248&rft.description=Question+about+Capitalization+%C2%B7+npm%2Fnpm%409c0b248&rft.identifier=https%3A%2F%2Fgithub.com%2Fnpm%2Fnpm%2Fcommit%2F9c0b24898b782e2bf43073bb1d836bbe67b339b3&rft.date=2011-08-06"> </span></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><a href="#cite_ref-34">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://github.com/npm/npm/commit/b88c37c1cced40e9e41402cc54a5efc3c33cd13e"><i>doc: remove FAQ · npm/npm@b88c37c.</i></a> In: <i>GitHub.</i> 25. November 2015,<span class="Abrufdatum"> abgerufen am 7. April 2016</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=doc%3A+remove+FAQ+%C2%B7+npm%2Fnpm%40b88c37c&rft.description=doc%3A+remove+FAQ+%C2%B7+npm%2Fnpm%40b88c37c&rft.identifier=https%3A%2F%2Fgithub.com%2Fnpm%2Fnpm%2Fcommit%2Fb88c37c1cced40e9e41402cc54a5efc3c33cd13e&rft.date=2015-11-25"> </span></span>
</li>
<li id="cite_note-35"><span class="mw-cite-backlink"><a href="#cite_ref-35">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://github.com/npm/npm-expansions"><i>npm/npm-expansions.</i></a> In: <i>GitHub.</i><span class="Abrufdatum"> Abgerufen am 7. April 2016</span>: „What does n-p-m stand for?“</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3ANpm+%28Software%29&rft.title=npm%2Fnpm-expansions&rft.description=npm%2Fnpm-expansions&rft.identifier=https%3A%2F%2Fgithub.com%2Fnpm%2Fnpm-expansions"> </span></span>
</li>
</ol></div><!--htdig_noindex--><div><div class="zim-footer">
Dieser Artikel wurde von <a class="external text" title="Zuletzt bearbeitet am 2025-10-16" href="https://de.wikipedia.org/wiki/?title=Npm_(Software)&oldid=260649622">Wikipedia</a> herausgegeben. Der Text ist unter <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.de">Creative Commons Attribution-Share Alike 4.0</a> verfügbar, sofern nicht anders angegeben. Für die Mediendateien können zusätzliche Bedingungen gelten.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>
</body></html>