Bonum Certa Men Certa

Microsoft GitHub Exposé — Part XVIII — The Story of NPM

Series parts:

  1. Microsoft GitHub Exposé — Part I — Inside a Den of Corruption and Misogynists
  2. Microsoft GitHub Exposé — Part II — The Campaign Against GPL Compliance and War on Copyleft Enforcement
  3. Microsoft GitHub Exposé — Part III — A Story of Plagiarism and Likely Securities Fraud
  4. Microsoft GitHub Exposé — Part IV — Mr. MobileCoin: From Mono to Plagiarism... and to Unprecedented GPL Violations at GitHub (Microsoft)
  5. Microsoft GitHub Exposé — Part V — Why Nat Friedman is Leaving GitHub


  6. Microsoft GitHub Exposé — Part VI — The Media Has Mischaracterised Nat Friedman's Departure (Effective Now)
  7. Microsoft GitHub Exposé — Part VII — Nat Friedman, as GitHub CEO, Had a Plan of Defrauding Microsoft Shareholders
  8. Microsoft GitHub Exposé — Part VIII — Mr. Graveley's Long Career Serving Microsoft's Agenda (Before Hiring by Microsoft to Work on GitHub's GPL Violations Machine)
  9. Microsoft GitHub Exposé — Part IX — Microsoft's Chief Architect of GitHub Copilot Sought to be Arrested One Day After Techrights Article About Him
  10. Microsoft GitHub Exposé — Part X — Connections to the Mass Surveillance Industry (and the Surveillance State)


  11. Microsoft GitHub Exposé — Part XI — Violence Against Women
  12. Microsoft GitHub Exposé — Part XII — Life of Disorderly Conduct and Lust
  13. Microsoft GitHub Exposé — Part XIII — Nihilistic Death Cults With Substance Abuse and Sick Kinks
  14. Microsoft GitHub Exposé — Part XIV — Gaslighting Victims of Sexual Abuse and Violence
  15. Microsoft GitHub Exposé — Part XV — Cover-Up and Defamation


  16. Microsoft GitHub Exposé — Part XVI — The Attack on the Autonomy of Free Software Carries on
  17. Microsoft GitHub Exposé — Part XVII — Backsliding Into 1990s-Style Digital Slavery by Microsoft
  18. YOU ARE HERE ☞ The Story of NPM


GitHub: Where everything comes to die



Summary: The time seems right to resume this series, more so now that the Software Freedom Conservancy (SFC) [1, 2] and the Free Software Foundation (FSF) [1, 2, 3] grapple with the legal chaos caused by Team Mono inside Microsoft's GitHub

A few years ago Microsoft bought NPM through its tentacle (mind the pun!) known as GitHub, in effect controlling more of the "supply chain" while hiring NSA veterans to run GitHub. This is a major security fiasco, a blunder in the making. Remember that when NPM ships malware the media rushes to blame the victims (like GNU/Linux users who receive that malware) instead of blaming the company responsible for actually sending that malware. Meanwhile, with GitHub Actions, many projects have foolishly outsourced the build process to "the clown" -- in essence losing control of the compiler, instead trusting Microsoft and the NSA to manage that for them. It's a sort of subsidy (selling CPU cycles) in exchange for control. Who by? Microsoft.

It has been months since we published the arrest record of Balabhadra (Alex) Graveley, whom we'll leave outside it for a moment. He has court hearings and it's possible he'll be behind bars for a very long time. Those who were connected to him or defended him have long regretted it, possibly left their job, or "resigned" to avoid public embarrassment. We'll come back to them later in this series and maybe we'll have some updates from the courts.

"Some sites announced that Microsoft had taken over NPM and that was it (they actually said "GitHub" to perpetuate the illusion that Microsoft and GitHub are separate entities)."As the state of journalism in general (not just on technical matters) is so appalling these days little actual investigation of the NPM takeover was conducted. Some sites announced that Microsoft had taken over NPM and that was it (they actually said "GitHub" to perpetuate the illusion that Microsoft and GitHub are separate entities).

A rather reliable source recently told us a few details about the NPM story; "I remember all that drama with TJ Holowaychuk leaving the NPM scene," our sourced recalled. "Wondering if that was related to Microsoft acquiring NPM."

What shocked me most at the time was the lack of press coverage or scrutiny. Like nothing actually happened! Or like it didn't matter...

"A bit off topic but that whole event seemed strange," our source noted. The motivation is still barely known or explored; it's shrouded in mystery as there's no actual business model other than taking control of people. NPM wasn't about making money; the same was true about GitHub. The way we see it, Microsoft is trying to swallow all the code and repos as well (NPM). It's about control.

"The way we saw it (at the time of the acquisition), NPM is a piece for Microsoft's "supply chain" plan, which also helps the NSA's objectives, especially at times of conflict."TJ's [Holowaychuk] departure "was a pretty big event," our source explained. "At that point in time TJ had written like 60% of the node.js projects that everyone uses. Mostly by himself. Some people thought he wasn't a real person for a long time. Like they thought he was a collective..."

The way we saw it (at the time of the acquisition), NPM is a piece for Microsoft's "supply chain" plan, which also helps the NSA's objectives, especially at times of conflict. They can remotely take over all sorts of things. Remember that they hired from the NSA for GitHub management. This is all very well documented. What sort of company would do this??? Heck, they can even plant back doors in downloads, custom-made or tailored to specific downloaders, never mind the above-mentioned compilation process. Why would anyone trust Microsoft after the NSA leaks? They work hand-in-glove with the NSA on back doors.

"TJ is just a legend and influenced my personal coding style," our source told us. "There was another issue with the guy who originally wrote node.js [...] He wrote it then quit [...] Joyent hired him..."

"Ryan Dahl apparently thinks writing node.js was a mistake [...] Interesting he's also from Rochester or just went to school there [as Graveley] is from there [and] they're about the same age..."

NPM was acquired by GitHub two years after the Microsoft acquisition. It was mentioned by Nat Friedman on 16 March 2020.

According to our source, TJ's "complaints about node.js mostly seemed technical, but who knows..."

As a side note, it's worth mentioning that node.js and OpenJS became a Microsoft infiltration vector inside the Linux Foundation, as noted in Techrights several times in the past.

Now that the FSF and SFC are writing a lot more about Copilot (see links in the summary above) we intend to revisit the topic, probably some time next Monday. Graveley will walk into the darkness or some prison cell while we're left to pick up and grapple with the damage he and his "best friends" the Friedmans have caused.

Recent Techrights' Posts

Ponzi Schemes Are Useful (to Corrupt CEOs)
Pathetic, corruptible so-called 'media' is bagging bribes to perpetuate the lies about "AI" (slop)
Body-Shaming Using Fakes
a lot of the people who casually claim "defamation" are themselves defaming loads of people every day
EPO People Power - Part XXIV - Today or Tomorrow You Should Write to National Representatives (Delegates) at the EPO in Your Country
Keep up the pressure!
Red Hat and IBM Layoffs, Staff Kept Quiet About it, WARN Act Skirted/WARN Notices Avoided
What a terrible company to be in
Slop Still Rare
So far a good start for 2026
 
Links 04/01/2026: War Without Borders, "Large Hadron Collider Being Shut Down"
Links for the day
Links 04/01/2026: US Imperialism in Greenland and Venezuela, "Climate Protesters Face Greater Risk of Crackdown Amid Rising Authoritarianism"
Links for the day
2026 Should be the Year We All Stop Saying "AI" and Call Things What They Really Are
Don't give anyone the satisfaction of this misguided belief there's any intelligence there
GNU/Linux at All-Time High in Algeria
In 2026 it hit a new all-time high
Online Mobbing (and Worse) Disguised as 'Free Speech'
People who say they believe in "free speech" have been trying hard to silence RMS and squash the FSF
A 'Cancer That Attaches Itself' to Bulgaria?
"Cancer" is what Microsoft called GNU/Linux
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, January 03, 2026
IRC logs for Saturday, January 03, 2026
GNU/Linux "Market Share" in Switzerland More Than Doubled Last Year, Based on statCounter
GNU/Linux continues its considerable growth
XBox Layoffs Imminent, More Appalling Sales Figures Published
Expect many layoffs in the gaming division
Gemini Links 03/01/2026: Climbing, Waking Up, and Social Control Media Woes
Links for the day
Links 03/01/2026: Growing Censorship, Another US Invasion, and Will Smith 'Cancelled'
Links for the day
Links 03/01/2026: Twitter Turns From Disinformation Powerhouse to Production and Dissemination of Child Pr0n, "New China Cybersecurity Law Becomes A Reality In 2026"
Links for the day
Gemini Links 03/01/2026: Formatting Text for Gopher and Text-only Websites
Links for the day
Unverified Claim: Mass Layoffs at Microsoft to Start Around Week 3 (or 4) of This Month
Let's wait and see if the claim above is from an insider who has inside knowledge
Firefox Fell Below 1% in Asia
less than 1 in 100 Web users is detected/assumed to be using Firefox
Links 03/01/2026: Ryanair Fines and Facebook Misleads Regulators
Links for the day
New Record High for GNU/Linux in Benelux in 2026
If the above trends stand (throughout the year), then we can begin talking more seriously about a post-GAFAM Europe
In the Search Engine Market, Microsoft is Falling Behind Russia's Yandex
The so-called 'AI industry' is a boy that cries wolf
A Year of Relaxation, But Also of Hardcore Whistleblowing
Expect industrial action some time soon
The More Influential Richard Stallman (RMS) Becomes, the More Aggressive Attacks on Him (and the FSF) Will Get
We've meanwhile noticed disinformation being spread in social control media
GNU/Linux Reaches All-Time High of 5% in Indonesia (Not Counting Chromebooks and Android)
There are also related events in Indonesia and SUSE in particular seems to have been popularised there
EPO People Power - Part XXIII - António Campinos Knows He's Extremely Vulnerable at This Time
Campinos should never have been put in charge
Gemini Links 03/01/2026: New Organisation System (Notebooks) and "2026 Already Off to an Amazing Start"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, January 02, 2026
IRC logs for Friday, January 02, 2026
The More Buzzwords a Corporation Resorts To...
buzzwords are a fool's way to compensate for or disguise a lack of knowledge
So You Should Definitely Call it "Slop" and Stop Saying "AI"
with more XBox/gaming layoffs being imminent the blowback will be fun to watch
Why Are We Still Using Voting Machines?
Voting machines still seem to me like an infantile cargo cult and an act of salesmanship (like various security theatre rituals at airports)
"Works for Me!"
Who knows best?
Why IBM Workers Like Techrights (Same Reason EPO Workers Do)
IBM will likely be a daily theme (high rate of recurrence)
Workers Fly Away From IBM's Red Hat (This Year a Lot of Red Hat Staff is "IBM")
The stock (share price) of IBM says nothing about what actually goes on
In 2025 We Contributed to the Headlessness of the OSI, But It's Not Over Yet
By airing some 'dirty laundry' about the OSI last year we contributed to its current state
Africa's Largest Population Sees Diminishing Impact of Windows
less than 1 in 10 Web requests in Nigeria comes from Windows
Russia Cuts Finnish Cables ("Hybrid War"), Finland Cuts Off Microsoft
the birthplace of Linux
Links 02/01/2026: Science, Patent Maximalism, and Public Domain Day
Links for the day
Gemini Links 02/02/2026: Books, Scams, and mkscript (a Script to Make Scripts)
Links for the day
Free Software is More Naturally Inclusive
large, intolerant, violent companies get painted as a glorious example of United Colours of Benetton
Strong Start for GNU/Linux This Year
based on statCounter
More Tools, Factorising Code
If some things in the site of Gemini capsules don't behave as expected, then that's likely due to a bug
Europe in 2026: Over 5% GNU/Linux, Not Counting Chromebooks
2026 has started strongly
State of Tech Journalism in 2026: Follow the Money
in order to understand what motivates an opinion piece one must follow the money
Slopfarm Says Microsoft's "Biggest Business" is the 'Business' Where It Loses Tens of Billions of Dollars
TOI still pretends to have a lot of output
At the Start of January 2025 Microsoft President Said Microsoft Would Spend 80 Billion Dollars on "AI" Data Centres. That Didn't Happen. Microsoft Laid Off 30,000 Workers, Debt Surged.
Maybe this coming Monday Microsoft will come up with more false promises and vapourware
Links 02/01/2026: Insurrectionist Attacks Musicians Critical of Him With Lawfare, Project Gutenberg Now Has Over 75,000 Books
Links for the day
Decline in LLM Slop About "Linux" is a Good Start for 2026
When the only remaining proponents of slop are slop, which is pretty much what's happening right now, the bubble is popping
EPO People Power - Part XXII - Contact Officials and Inform Your National Representatives (Delegates) of the EPO's Cocainegate
Europe's largest media intentionally covers up serious scandals in Europe's second-largest institution
Slopwatch Still Dead, Not Enough LLM Slop About "Linux"
this is the desirable thing
LibXML2 Will Carry on (Without or With the Name "LibXML2")
The proprietary software boosters are projecting
Gemini Links 02/01/2026: ThinkPad, SHARP Zaurus, Lagrange Handheld Support
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, January 01, 2026
IRC logs for Thursday, January 01, 2026