Hackernews posts about NPM
NPM is a package manager for JavaScript that allows developers to easily install and manage dependencies in their projects, serving as a central registry for millions of open-source packages.
Related:
Ledger
- Postmortem: TanStack NPM supply-chain compromise (tanstack.com)
- NPM website was down (status.npmjs.org)
- Official SAP NPM packages compromised to steal credentials (www.bleepingcomputer.com)
- Bitwarden CLI NPM package has been compromised (opensourcemalware.com)
- Postmortem: TanStack NPM supply-chain compromise (tanstack.com)
- Mini Shai-Hulud: Bun Payloads Hit SAP NPM Packages (www.stepsecurity.io)
- OpenAI caught NPM supply chain chaos after employeedevices compromised (www.theregister.com)
- Malicious node-IPC Versions Published to NPM (github.com)
- Our response to the TanStack NPM supply chain attack (openai.com)
- Mistral AI's NPM package was compromised (github.com)
- Another NPM supply chain worm is tearing through dev environments (www.theregister.com)
- Staged Publishing for NPM Packages (docs.npmjs.com)
- Staged Publishing for NPM Packages (docs.npmjs.com)
- AI-powered NPM deprecation tracker with dependency tree Ghost Detection (www.stackgraveyard.dev)
- NPM: Putting the Brown in Brownout (ryanbigg.com)
- More live NPM packages attributed to Axios threat actors (opensourcemalware.com)
- NPM invalidates use of fine-grained tokens that bypass 2FA (docs.npmjs.com)
- TeamPCP Campaign Spreads to NPM via a Hijacked Bitwarden CLI (research.jfrog.com)