# npm (Node Package Manager)

URL: https://softwaredictionary.org/terms/npm
Category: Web Development
Last updated: 2026-10-03

In short: npm is Node.js's default package manager and the world's largest software registry; it downloads a project's dependencies and tracks their versions.

## What is npm?

npm was created by Isaac Z. Schlueter in 2010 and ships with every installation of Node.js. It has two parts: a command-line tool that installs and manages packages, and the npm registry, an online store of millions of open-source JavaScript packages that anyone can publish to. It has been owned by GitHub since 2020.

A project lists its dependencies in a `package.json` file, together with scripts such as `test` and `build`. Running `npm install` downloads the packages, and the packages they depend on, into a `node_modules` folder and records the exact versions in `package-lock.json`, so every developer and server gets the same set. Versions follow semantic versioning, and ranges such as `^4.2.0` allow compatible updates.

`npm run` executes the scripts from `package.json`, and `npx` runs a package's command without installing it globally, for example to create a new project. Alternatives such as pnpm, Yarn and Bun use the same registry and `package.json`, but install packages differently, often faster or with less disk space.

A common misconception is that npm is only for Node.js on servers. Most frontend tools and libraries, such as React, Vite and TypeScript, are installed through it as well. Because installing a package can run its install scripts and pulls in many indirect dependencies, the registry has also been a target of supply chain attacks, so lockfiles and audits matter.

## Key takeaways

- npm is Node.js's package manager and the largest JavaScript package registry.
- package.json lists dependencies and scripts; package-lock.json pins exact versions.
- npm install fills node_modules; npm run executes scripts; npx runs package commands.
- pnpm, Yarn and Bun are alternatives that use the same registry.
- Lockfiles and audits help guard against supply chain attacks.

## Example: A package.json with scripts and dependencies

```json
{
  "name": "my-app",
  "version": "1.0.0",
  "scripts": {
    "dev": "vite",
    "test": "vitest"
  },
  "dependencies": {
    "react": "^19.0.0"
  },
  "devDependencies": {
    "vite": "^7.0.0",
    "vitest": "^3.0.0"
  }
}
```

## Frequently asked questions

**What is the difference between npm and npx?**

npm installs and manages packages. npx runs a command from a package, downloading it temporarily if it isn't installed, which is handy for one-off tools such as project generators.

**What is package-lock.json?**

A file npm writes that records the exact version of every installed package, including indirect ones, so that installs on other machines produce the same result. It should be committed to version control.

**What is the difference between npm, Yarn and pnpm?**

All three install packages from the same registry using package.json. Yarn and pnpm were created to be faster or more efficient; pnpm, for example, stores each package version once on disk and links it into projects.

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
