
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
NPM registry manager mirror can help you easy and fast switch between different npm registries
Another version of nrm, just for learning something interesting.
npm i -g nrmm
List all available registries:
$ nrmm ls
npm ---------- https://registry.npmjs.org/
yarn ---------- https://registry.yarnpkg.com/
tencent ---------- https://mirrors.cloud.tencent.com/npm/
cnpm ---------- https://r.cnpmjs.org/
* taobao ---------- https://registry.npmmirror.com/
npmMirror ---------- https://skimdb.npmjs.com/registry/
Show current registry:
nrmm current
Switch registry:
$ nrmm use # or npm use <registry>
? Select a registry (Use arrow keys)
> npm
yarn
tencent
cnpm
taobao
npmMirror
Add custom registry:
nrmm add
Delete custom registry:
nrmm del
Edit custom registry:
nrmm edit
Rename registry:
nrmm rename
Test the response time of registry:
nrmm ping [registry]
MIT
FAQs
NPM registry manager mirror can help you easy and fast switch between different npm registries
The npm package nrmm receives a total of 2 weekly downloads. As such, nrmm popularity was classified as not popular.
We found that nrmm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.