Hackernews posts about NPM
NPM is a package manager for JavaScript that allows developers to easily install and manage dependencies in their projects, serving as a central registry for millions of open-source packages.
Related:
Ledger
- Postmortem: TanStack NPM supply-chain compromise (tanstack.com)
- Staged publishing and new install-time controls for npm (github.blog)
- New IronWorm malware hits 36 packages in NPM supply-chain attack (www.bleepingcomputer.com)
- Postmortem: TanStack NPM supply-chain compromise (tanstack.com)
- OpenAI caught NPM supply chain chaos after employeedevices compromised (www.theregister.com)
- Malicious node-IPC Versions Published to NPM (github.com)
- New IronWorm malware hits 36 packages in NPM supply-chain attack (www.bleepingcomputer.com)
- A 176-Package NPM Campaign Built to Beat Your Internal Dependencies (www.sonatype.com)
- Our response to the TanStack NPM supply chain attack (openai.com)
- Mistral AI's NPM package was compromised (github.com)
- New Shai-Hulud malware wave compromises 600 NPM packages (itnerd.blog)
- Red Hat packages backdoored through its official NPM channel (arstechnica.com)
- Staged Publishing for NPM Packages (docs.npmjs.com)
- Miasma NPM Supply Chain Attack: Self-Spreading Worm via Phantom Gyp (www.stepsecurity.io)
- NPM staged publishing setup with approximately one click per package (lavamoat.github.io)
- Staged Publishing for NPM Packages (docs.npmjs.com)
- AI-powered NPM deprecation tracker with dependency tree Ghost Detection (www.stackgraveyard.dev)