"NPM Registry Users Download 2.1B Deprecated Packages Weekly, Researchers Say"
"NPM Registry Users Download 2.1B Deprecated Packages Weekly, Researchers Say"
Researchers from Aqua Security's Team Nautilus conducted a statistical analysis of the top 50,000 most downloaded packages in the NPM registry, revealing that users download deprecated packages an estimated 2.1 billion times per week. The researchers stress that deprecated, archived, and orphaned NPM packages may contain unpatched or unreported vulnerabilities, putting projects that rely on them at risk.