npm is a package manager for JavaScript, widely used in open source. It was the platform targeted in the debug, chalk, and axios supply chain attacks. npm v12 introduced security changes like disabling lifecycle scripts by default and scanning new publishes for malware.