motyl.dev
TrendingNewsletterBlogNewsAbout
Support
Grzegorz Motyl

© 2026 Grzegorz Motyl. Raising the bar of professional software development.

GitHubBlueskyEmail
Home
News
Blog
Me
    /
    motyl.dev
    TrendingNewsletterBlogNewsAbout
    Support
    1. Home
    2. News
    3. npm Supply Chain Attacks, Leaked Source Maps, and Copy-Paste UI Components

    npm Supply Chain Attacks, Leaked Source Maps, and Copy-Paste UI Components

    Published on 02.04.2026

    #dailydev
    #frontend
    #webdev
    motyl.dev<div></div></>FRONTEND

    The Axios Supply Chain Attack That Should Keep You Up at Night

    TLDR: Two malicious versions of axios, one of the most downloaded npm packages on the planet, were published on March 30-31, 2026 after an attacker hijacked the primary maintainer's npm account. The packages installed a remote access trojan on developer machines across macOS, Windows, and Linux. If you ran npm install during that window, treat the machine as compromised.

    Axios npm Package Compromised With Remote Access Trojan


    Anthropic Accidentally Ships Claude Code's Entire Source Code

    TLDR: Anthropic shipped a 57-59MB source map file in version 2.1.88 of the Claude Code npm package, exposing over 500,000 lines of TypeScript across nearly 1,900 files. This was reportedly the second time such a leak occurred, with a similar incident in February 2025.

    Claude Code Source Leaked via npm Source Maps: Lessons for Every DevOps Team


    Spell UI: Copy-Paste React Components for Design Engineers

    TLDR: Spell UI is a collection of React UI components built for design engineers, designed to drop into projects using Tailwind CSS with no installation overhead beyond copying the component code.

    Spell UI


    AI Elements: A Component Registry for AI-Native Apps

    TLDR: AI Elements is a shadcn/ui-based component library and custom registry built specifically for AI-native applications, covering chat interfaces, IDE-style code editors, and workflow visualization canvases.

    AI Elements

    ☕ Knowledge costs tokens,fuel meHelp me keep the content flowing
    External Links (4)

    Axios npm Package Compromised With Remote Access Trojan

    laravel-news.com

    Claude Code Source Leaked via npm Source Maps: Lessons for Every DevOps Team

    app.daily.dev

    Spell UI

    app.daily.dev

    AI Elements

    app.daily.dev

    Sign in to bookmark these links
    Previous
    The 2-Hour Workday Joke That Says Something True About AI Agents
    Next
    RedwoodSDK 1.0, CSS Renders DOOM, and Cloudflare Is Everywhere This Week
    Grzegorz Motyl

    © 2026 Grzegorz Motyl. Raising the bar of professional software development.

    GitHubBlueskyEmail