How it works
The npm registry is the world's largest software registry, with millions of JavaScript packages. Running npm install reads package.json, fetches every dependency (and their dependencies) into a node_modules folder, and records the exact versions in package-lock.json. npm run executes the scripts a project defines, such as dev, build and test.
npx fetches a package temporarily and runs its command, which is how one-off tools and project starters work: npx create-next-app sets up a new app without installing anything globally. GitHub has owned npm since 2020. Because anyone can publish, the registry has seen hijacked and malicious packages, so lockfiles, two-factor sign-in for publishers and care with new dependencies all matter. pnpm, Yarn and Bun install from the same registry.
npm and npx pros and cons
Pros
- Ships with Node.js, so there is nothing extra to install
- Millions of packages in one registry
- Works with every tool, host and CI service out of the box
- npx turns one-off tools and project starters into a single command
Cons
- Slower installs and bigger node_modules folders than pnpm or Bun
- Deep dependency trees make supply-chain attacks a real risk
- The flat node_modules lets code import packages it never declared
When to use npm and npx
Pick it when
- You want the default that every tutorial and tool assumes
- Small and medium projects where install speed is not a problem
- Publishing your own packages for others to install
Skip it when
- Large monorepos, where pnpm's workspaces and shared store save real time
npm and npx pricing
Free tier
The CLI and public packages are free. Private packages cost about $7 a month for a personal Pro account, or $7 per member a month for an organisation.
npm and npx pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost
npm and npx vs the alternatives
Related terms
More in Dev workflow and DevOps
Packages