Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungI audited my own ML linter and had to withdraw its best evidence(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungQuantum Result Validation for Distributed Computing Systems(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungJWT Authentication and Role-Based Access Control in LocalHands(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungStochastic Parrot or Alien Mind?(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungBuilding AI for the Physical World Is a Different Engineering Problem(21.09.2026 um 22:58 Uhr)
Sichere ProgrammierungI audited my own ML linter and had to withdraw its best evidence(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungQuantum Result Validation for Distributed Computing Systems(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungJWT Authentication and Role-Based Access Control in LocalHands(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungStochastic Parrot or Alien Mind?(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungBuilding AI for the Physical World Is a Different Engineering Problem(21.09.2026 um 22:58 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

if npm hallucinates versions, check your root

So about a year ago, I started getting this strange npm issue, where the terminal was detecting v17.9.1, eventhough I was using a later version. This started causing npm i, npm run dev, etc to stop working as I would be prompted to upgrade…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

So about a year ago, I started getting this strange npm issue, where the terminal was detecting v17.9.1, eventhough I was using a later version. This started causing npm i, npm run dev, etc to stop working as I would be prompted to upgrade my node version.



I asked alot of my buddies, scoured stackoverflow and reddit, asked gpt and claude, but it seemed the issue was kind of unheard of to an extent. I went as far as ground up reinstalling npm, nvm, and node. Still, no luck. Nvm didnt even see any v17 installed. I kind of left it at that.



So I started digging myself.



The premise of the issue was something like this (this is a recent example)




$ nvm use
Now using node v22.12.0 (npm v10.9.0)
$ npm run dev

> dev
> react-router dev

️⚠️ Oops, Node v17.9.1 detected. react-router requires a Node version greater than 20.






The gist of it is:



When you run something like npm run dev, npm modifies the PATH by prepending node_modules/.bin directories



The search order goes:




/Users/*/node_modules/.bin/ 
/Users/*/Documents/node_modules/.bin/
/Users/*/Documents/GitHub/node_modules/.bin/
[...your project's node_modules...]
[...then your normal PATH with nvm...]






The issue with me, is a rouge npm package called "node" (v17.9.1) randomly ended up in the home directory:

/Users/*/node_modules/node/bin. So when npm executes node, it would pick up the version through that first.



So why did npm --version not pick this up? That's because no npm PATH manipulation had occurred yet, and the shell used the normal PATH where nvm's Node comes first. And saw v22.12.0 as expected.



The fix: Just delete the random node module and it should be good to go. I don't even know how it ended up there if I'm completely honest, maybe I was tired after a long day of capstone grinding.



TLDR: don't be dumb like me and accidentally install node into your home directory and forget about it...there will be reprecusions. If you do, just fix it lol.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten if npm hallucinates versions, check your root

Thematisch verwandte Begriffe: hallucinates, versions, check, your · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-79918 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick