Installing an npm package means downloading code someone else wrote and adding it to your project
An npm package is a folder of code that does one specific thing — validate email addresses, resize images, connect to a database, or thousands of other tasks. When you install a package, npm downloads it from the npm registry (a public library of code) and puts it in a folder called node_modules inside your project. Your code can then use that package by importing it.
The basic command is one line: npm install package-name. But what happens before and after that line, and which packages you actually need, depends on your project setup and what you're trying to build.
Key Takeaways
- You need Node.js installed on your computer first — npm comes with it — and a project folder with a package.json file.
- The command npm install package-name downloads the package and all its dependencies, then saves the package name to package.json so others know what your project needs.
- Use npm install --save-dev package-name for packages you only need while developing, like testing tools or code formatters.
- After you install a package, you import it in your code with const packageName = require('package-name') or import packageName from 'package-name' depending on your project type.
- The node_modules folder gets large and should never be shared — instead, share package.json, and others run npm install to download the same packages.
Check that Node.js and npm are already on your computer
npm is a command-line tool that comes bundled with Node.js. If you have Node.js installed, you have npm. Open a terminal (Command Prompt on Windows, Terminal on Mac or Linux) and type node --version and npm --version. If both return version numbers, you're ready to go. If not, download Node.js from nodejs.org — the Long Term Support (LTS) version is the safest choice for most people.
After you install Node.js, close and reopen your terminal so it recognizes the new commands.
Create or navigate to your project folder and initialize npm
A project folder is just a regular folder on your computer where your code lives. Open a terminal, navigate to that folder using cd path/to/your/folder, and check whether a file called package.json already exists. If it does, skip to the next section. If it doesn't, run npm init.
The npm init command asks you a series of questions — project name, description, entry point, and so on. You can press Enter to accept the defaults for most of them. When it finishes, you'll have a package.json file in your folder. This file is a record of every package your project depends on, and it's the file you share with others so they know what to install.
Run the install command for the package you want
Once you have a package.json file, installing a package is straightforward. In your terminal, still inside your project folder, type npm install package-name and press Enter. Replace package-name with the actual name of the package — for example, npm install lodash or npm install express.
npm downloads the package and all the other packages it depends on (called dependencies), puts them in a folder called node_modules, and updates your package.json file to record that you installed it. This usually takes a few seconds to a minute depending on the package size and your internet speed.
If you're not sure whether a package exists or what its exact name is, search for it on npmjs.com. The site shows you the package name, what it does, how many people use it, and when it was last updated.
Understand the difference between regular and development-only packages
Some packages your code actually runs — like a database library or a web framework. Other packages you only use while you're writing code — like a testing tool, a code formatter, or a linter that checks for mistakes. npm calls these two categories dependencies and devDependencies.
When you run npm install package-name, npm assumes it's a regular dependency and saves it to the "dependencies" section of package.json. If it's a development-only tool, use npm install --save-dev package-name instead, and npm saves it to "devDependencies" instead. This matters because when someone else installs your project for production (to actually run it), they can skip the devDependencies and save download time and disk space.
Common devDependencies include Jest (for testing), Prettier (for formatting code), and ESLint (for catching mistakes). If you're unsure, the package's documentation on npmjs.com usually says whether it's meant to be a regular or dev dependency.
Import the package in your code and use it
After npm installs a package, you can use it in your code. The way you import it depends on whether your project uses CommonJS or ES modules — two different ways of organizing code. Most newer projects use ES modules, which look like import lodash from 'lodash'. Older projects or Node.js scripts often use CommonJS, which looks like const lodash = require('lodash').
Check your project's package.json file — if it has "type": "module", use the import syntax. If that line is missing or says something else, use the require syntax. The package's documentation on npmjs.com shows examples of how to import and use it.
After you import the package, you can call its functions or use its objects just like any other code in your project. For example, if you installed lodash, you might write lodash.map(array, function) to transform an array.
Manage your packages over time
As your project grows, you'll install more packages. Run npm list in your terminal to see everything you've installed and what version each one is. Run npm update to upgrade all packages to newer versions (within the limits set in package.json). Run npm uninstall package-name to remove a package you no longer need.
Never edit the node_modules folder directly — it's generated from package.json and can be recreated anytime by running npm install with no arguments. If you're sharing your project with others, add node_modules to a .gitignore file so it doesn't get committed to version control. Others can then run npm install themselves to download the exact same packages listed in package.json.
Frequently Asked Questions
What does "npm ERR! 404" mean when I try to install a package?
It means the package name doesn't exist in the npm registry, or you misspelled it. Double-check the package name on npmjs.com — package names are case-sensitive and sometimes include hyphens or underscores. If the name is correct, the package may have been removed from the registry.
Why is node_modules so large and slow to download?
When you install a package, npm also installs every package that package depends on, and every package those depend on, and so on. A single package can pull in dozens of dependencies. This is normal. Never commit node_modules to version control — instead, share package.json and package-lock.json, and others run npm install to recreate it.
Can I install a specific version of a package?
Yes. Run npm install package-name@1.2.3 to install version 1.2.3 specifically. You can also use npm install package-name@latest for the newest version or npm install package-name@"^1.2.0" to install any version starting with 1.2. The package documentation usually recommends which version to use.
What's the difference between package.json and package-lock.json?
package.json lists the packages you want and the version ranges you're willing to accept. package-lock.json records the exact versions that were installed. Always commit both to version control — package-lock.json ensures that everyone working on the project installs identical versions, preventing "it works on my machine" problems.
Do I need to install packages every time I open my project?
No. Once you've run npm install, the packages stay in node_modules. You only need to run npm install again if you pull new code from version control that has different packages, or if you delete node_modules and want to recreate it from package.json.