Supply-Chain Security

Supply-Chain Security Across Ecosystems

Every install in this chapter ran code written by strangers, and the tools trusted it by default. MERN Stack Development, Security and the Supply Chain covers npm 2,036 audit, judging a package before you add it, and Node's permission model. This section looks at the attacks themselves, which work the same way on npm, PyPI 2,431 and crates.io, reproduces two of them safely with the Verdaccio registries of Verdaccio, and shows the defenses the managers added in 2025 and 2026.

Subsections