Bonum Certa Men Certa

Microsoft GitHub Exposé — Part XVIII — The Story of NPM

Series parts:

  1. Microsoft GitHub Exposé — Part I — Inside a Den of Corruption and Misogynists
  2. Microsoft GitHub Exposé — Part II — The Campaign Against GPL Compliance and War on Copyleft Enforcement
  3. Microsoft GitHub Exposé — Part III — A Story of Plagiarism and Likely Securities Fraud
  4. Microsoft GitHub Exposé — Part IV — Mr. MobileCoin: From Mono to Plagiarism... and to Unprecedented GPL Violations at GitHub (Microsoft)
  5. Microsoft GitHub Exposé — Part V — Why Nat Friedman is Leaving GitHub


  6. Microsoft GitHub Exposé — Part VI — The Media Has Mischaracterised Nat Friedman's Departure (Effective Now)
  7. Microsoft GitHub Exposé — Part VII — Nat Friedman, as GitHub CEO, Had a Plan of Defrauding Microsoft Shareholders
  8. Microsoft GitHub Exposé — Part VIII — Mr. Graveley's Long Career Serving Microsoft's Agenda (Before Hiring by Microsoft to Work on GitHub's GPL Violations Machine)
  9. Microsoft GitHub Exposé — Part IX — Microsoft's Chief Architect of GitHub Copilot Sought to be Arrested One Day After Techrights Article About Him
  10. Microsoft GitHub Exposé — Part X — Connections to the Mass Surveillance Industry (and the Surveillance State)


  11. Microsoft GitHub Exposé — Part XI — Violence Against Women
  12. Microsoft GitHub Exposé — Part XII — Life of Disorderly Conduct and Lust
  13. Microsoft GitHub Exposé — Part XIII — Nihilistic Death Cults With Substance Abuse and Sick Kinks
  14. Microsoft GitHub Exposé — Part XIV — Gaslighting Victims of Sexual Abuse and Violence
  15. Microsoft GitHub Exposé — Part XV — Cover-Up and Defamation


  16. Microsoft GitHub Exposé — Part XVI — The Attack on the Autonomy of Free Software Carries on
  17. Microsoft GitHub Exposé — Part XVII — Backsliding Into 1990s-Style Digital Slavery by Microsoft
  18. YOU ARE HERE ☞ The Story of NPM


GitHub: Where everything comes to die



Summary: The time seems right to resume this series, more so now that the Software Freedom Conservancy (SFC) [1, 2] and the Free Software Foundation (FSF) [1, 2, 3] grapple with the legal chaos caused by Team Mono inside Microsoft's GitHub

A few years ago Microsoft bought NPM through its tentacle (mind the pun!) known as GitHub, in effect controlling more of the "supply chain" while hiring NSA veterans to run GitHub. This is a major security fiasco, a blunder in the making. Remember that when NPM ships malware the media rushes to blame the victims (like GNU/Linux users who receive that malware) instead of blaming the company responsible for actually sending that malware. Meanwhile, with GitHub Actions, many projects have foolishly outsourced the build process to "the clown" -- in essence losing control of the compiler, instead trusting Microsoft and the NSA to manage that for them. It's a sort of subsidy (selling CPU cycles) in exchange for control. Who by? Microsoft.

It has been months since we published the arrest record of Balabhadra (Alex) Graveley, whom we'll leave outside it for a moment. He has court hearings and it's possible he'll be behind bars for a very long time. Those who were connected to him or defended him have long regretted it, possibly left their job, or "resigned" to avoid public embarrassment. We'll come back to them later in this series and maybe we'll have some updates from the courts.

"Some sites announced that Microsoft had taken over NPM and that was it (they actually said "GitHub" to perpetuate the illusion that Microsoft and GitHub are separate entities)."As the state of journalism in general (not just on technical matters) is so appalling these days little actual investigation of the NPM takeover was conducted. Some sites announced that Microsoft had taken over NPM and that was it (they actually said "GitHub" to perpetuate the illusion that Microsoft and GitHub are separate entities).

A rather reliable source recently told us a few details about the NPM story; "I remember all that drama with TJ Holowaychuk leaving the NPM scene," our sourced recalled. "Wondering if that was related to Microsoft acquiring NPM."

What shocked me most at the time was the lack of press coverage or scrutiny. Like nothing actually happened! Or like it didn't matter...

"A bit off topic but that whole event seemed strange," our source noted. The motivation is still barely known or explored; it's shrouded in mystery as there's no actual business model other than taking control of people. NPM wasn't about making money; the same was true about GitHub. The way we see it, Microsoft is trying to swallow all the code and repos as well (NPM). It's about control.

"The way we saw it (at the time of the acquisition), NPM is a piece for Microsoft's "supply chain" plan, which also helps the NSA's objectives, especially at times of conflict."TJ's [Holowaychuk] departure "was a pretty big event," our source explained. "At that point in time TJ had written like 60% of the node.js projects that everyone uses. Mostly by himself. Some people thought he wasn't a real person for a long time. Like they thought he was a collective..."

The way we saw it (at the time of the acquisition), NPM is a piece for Microsoft's "supply chain" plan, which also helps the NSA's objectives, especially at times of conflict. They can remotely take over all sorts of things. Remember that they hired from the NSA for GitHub management. This is all very well documented. What sort of company would do this??? Heck, they can even plant back doors in downloads, custom-made or tailored to specific downloaders, never mind the above-mentioned compilation process. Why would anyone trust Microsoft after the NSA leaks? They work hand-in-glove with the NSA on back doors.

"TJ is just a legend and influenced my personal coding style," our source told us. "There was another issue with the guy who originally wrote node.js [...] He wrote it then quit [...] Joyent hired him..."

"Ryan Dahl apparently thinks writing node.js was a mistake [...] Interesting he's also from Rochester or just went to school there [as Graveley] is from there [and] they're about the same age..."

NPM was acquired by GitHub two years after the Microsoft acquisition. It was mentioned by Nat Friedman on 16 March 2020.

According to our source, TJ's "complaints about node.js mostly seemed technical, but who knows..."

As a side note, it's worth mentioning that node.js and OpenJS became a Microsoft infiltration vector inside the Linux Foundation, as noted in Techrights several times in the past.

Now that the FSF and SFC are writing a lot more about Copilot (see links in the summary above) we intend to revisit the topic, probably some time next Monday. Graveley will walk into the darkness or some prison cell while we're left to pick up and grapple with the damage he and his "best friends" the Friedmans have caused.

Recent Techrights' Posts

Gemini Links 26/05/2026: A Year of Composting, Fedora Bricks Itself and Infuriates Users With Slop and Wayland (Not What Users Want, What IBM Wants), Crawlers on Geminispace a Nuisance
Links for the day
Good Thing When Home Appliances Are Ancient Antiques
dealing with the alarm has cost only time
The Bloating of the Web Contributes to Global Warming and Causes Burnout (Slowdown, Hardware Erosion, Waste)
This problem isn't limited to weather sites or subsites
Why It's Ludicrous to Call Us "Microsoft Haters"
Even if clustered together, news items still cover a broad spectrum (or spectra) of issues
 
Slop is a Passing Fad, It's About Faking Productivity (Plagiarism, Misinformation, and False Positives)
Slop is a bubble. Some people accept it later than others.
Anderon - Like Kyndryl - Could be Far Deeper in Debt Than Its Alleged Worth (Vapourware)
Time will tell, but it seems like a Federal-enabled (by the Federal Government) accounting scam, nothing more, nothing less
The Media That Keeps Covering "AI" Because the Pushers of It Pay for Spam
23 times in the page they mention "AI"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, May 26, 2026
IRC logs for Tuesday, May 26, 2026
Codecs and Software Patents - Part XI - The Stance of RMS (Dr. Stallman) Reassured GNU Regarding AV1
cautioned against software patents since the early 90s if not earlier
Google: We Are Locking You Out of Your Account (Since 15+ Years Ago) Because You Don't Have a Spyphone We Remotely Control
Google (GAFAM) is an evil company deep in debt
Red Hat: Bluewashing by IBM, Followed by RAs (Layoffs)
We could use some hints or evidence related to this
Links 26/05/2026: "Making the Digital Physical"; "The Medical System Abandons Women When They Are Most Vulnerable"
Links for the day
While US Government Greenlights (or Bluelights) Bailouts for IBM Some Foreign Governments Blacklist It
"Albany leadership doesn’t know what they are doing but are damn good at pretending they do."
IBM Bailouts and the IBM People Inside the Administration
It seems possible/plausible that it is bailout money down the drain or that this money will never arrive at all
Links 26/05/2026: Lithium Batteries Causing Fires (Even on Planes), 'Timmy' the Whale Dies
Links for the day
Pursuing Facts in an Age of Lies and 'Hallucinations' (Falsehoods Without Anyone Accountable, They Try Calling Computer-Generated Lies or Forgeries "Intelligence").
Our aim is to relay information while bypassing gossip networks like social control media and slop in "search" clothing
Computer-Generated Legal Filings Get You Reported to the Solicitors Regulation Authority (SRA)
We'll write a lot more about this in the future
EPO "Cocaine Communication Manager" - Part XII - In the Second-Largest Institution in Europe One Can Take Paid 'Sick Leave' for Doing Cocaine, Then Come Back
Cocaine addicts in the management were bullying colleagues. They're still in charge.
Sites in Their Twenties
We currently run concurrently a handful of series and have a lot more in the backlog
SLAPP Censorship - Part 88 Out of 200: Brett Wilson LLP is Defaming Trans People in America Because Garrett Pays Hired Guns to Silence Them
Garrett is scoring many own goals this year
Sloppy "Resource Action," (RA) or IBM Layoff, Leads to Another IBM Lawsuit, Alleging IBM Tries to Pass Liability to Algorithms
IBM is meanwhile resorting to slop to gaslight its remaining shareholders
The Latest IBM Layoff Rumours
What has happened to the company that invented so much of modern computing?
Holy See Recognises the Threat of GAFAM and Slop
Will the Holy See move away from GAFAM?
The Old Ways of Computing Were Objectively Better
Not as fast, but certainly much better
Social Control Media is a Giant Waste of Time (and There Are No Future Remedies for This)
Social Control Media is considered unhealthy to young people, but it is also collectively unhealthy to nations and nation-building
Codecs and Software Patents - Part X - Florian Müller Still Muddying the Waters for FOSS, Using Software Patents
Some things never change...
Gemini Links 26/05/2026: Slop Bug Reports and Crawlers Considered Evil
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, May 25, 2026
IRC logs for Monday, May 25, 2026
Slop Causes Global Warming
in some parts of the world people die from overheat (heat strokes) as temperatures reach almost 50 degrees as early as May in the northern hemisphere
Vatican Speaks Out Against Slop, Promoting Instead "Truth, Dignity of Work, Social Justice, and Peace."
Religion (no matter which) does not oppose machines, but LLMs aren't useful machines
SLAPP Censorship - Part 87 Out of 200: Access to Justice
this part will be short
A Promise IBM/Red Hat Could Not Keep
"all about control, not so much optics."
Links 25/05/2026: Russia Lobbing Oreshnik Ballistic Missile Again, Slop Comes Under More Fire
Links for the day
Gemini Links 25/05/2026: Injury in Gym and Abusive LLMs DDoSing Software Developers While Misusing Their Code
Links for the day
A 'Bank Holiday' When National Debt Doubles in a Decade
Maybe it's time to rename "Bank Holidays"
Links 25/05/2026: Lingering Environmental Concerns and Domain Registrars Targeted for Unmasking
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 24, 2026
IRC logs for Sunday, May 24, 2026