
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
pkg-rename
Advanced tools
# npm
npx pkg-rename@latest --old-name
# pnpm
pnpm dlx pkg-rename@latest --old-name
# bun
bunx pkg-rename@latest --old-name
# deno
deno run -A npm:pkg-rename@latest --old-name
To see the available options run the command: npx pkg-rename@latest --help
Options:
-V, --version output the version number
-o, --old-name <old-name> The old package name and version that you want to deprecate
-n, --new-name <new-name> The new package name
-m, --message <message> Package deprecation message
-h, --help display help for command
Published under the MIT license.
Made by @selemondev and community 💛
FAQs
A tiny CLI to help you rename your package and publish it to NPM ✨
We found that pkg-rename demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.