Hackernews posts about NPM
NPM is a package manager for JavaScript that allows developers to easily install and manage dependencies in their projects, serving as a central registry for millions of open-source packages.
Related:
Ledger
- NPM publish-time malware scanning and dual-use metadata (github.blog)
- NPM publish-time malware scanning and dual-use metadata (github.blog)
- North Korea-linked hackers targeted major NPM packages (aws.amazon.com)
- ChainDrop worm crawls into NPM supply chain, evades standard defenses (www.theregister.com)
- NPM Left-Pad Incident (en.wikipedia.org)
- GitHub Account Breach Fuels Shai-Hulud NPM Supply Chain Attack (www.esecurityplanet.com)
- ChainDrop NPM supply-chain attack infects packages (www.bleepingcomputer.com)
- Please add min-release-age to your .npmrc (www.endorlabs.com)
- The keyv worm ate 400 NPM packages in 90 minutes (installsafe.io)
- ChainDrop worm crawls into NPM supply chain, evades standard defenses (www.theregister.com)
- Show HN: Sandbox the install step of any NPM package (www.npmjs.com)
- Show HN: Day to day windows reminder CLI (NPM) (www.npmjs.com)
- Worm compromises popular NPM packages (securitylabs.datadoghq.com)
- Shai Hulud campaign strikes NPM again (research.jfrog.com)
- Bundlephobia – Find the cost of adding an NPM package to your bundle (bundlephobia.com)
- North Korea NullReceiver Hides Malware in NPM (opensourcemalware.com)
- ChainDrop: A Self-Propagating NPM Worm (unit42.paloaltonetworks.com)
- Making More NPM Packages Work with JsDelivr ESM Mode (www.jsdelivr.com)
- Shai-Hulud: What an NPM supply-chain hack reveals about the limits of provenance (ctolunchnyc.substack.com)
- NPM Implements Pre-Publication Malware Scanning, but Will It Work? (opensourcemalware.com)