Node Weekly issue #634 covers several topics: Matteo Collina explains why Node.js cannot be hardened against prototype pollution at the core level, noting the real fix must happen at the boundary where untrusted JSON is parsed. Security highlights include upcoming July 27 Node.js security releases for versions 22.x, 24.x, and 26.x addressing a HIGH severity issue, plus analysis of an AsyncAPI npm supply chain compromise and a study on LLM-generated fake npm package names (slopsquatting). Other news includes Bun 1.4 teasing its biggest Node.js compatibility jump since v1.0, pnpm releases 11.11–11.14 with native workspace release management and a doctor command, ESLint official codemods for v8→v9 and v9→v10 migrations, Execa 10.0 with a trimmed API and new stream features, and BotKit for building standalone ActivityPub bots in JavaScript.