On June 18, 2026, Node.js released updates for its active release lines, including Node 22.23.0 (LTS) and Node 24.17.0. These releases contained security patches, notably a fix for a Response Queue Poisoning vulnerability in http.Agent.
A massive NPM supply chain attack has compromised foundational packages like Chalk, affecting over 1 billion weekly downloads. We dissect the crypto-stealing malware and show you how to protect your projects immediately.