Hackernews posts about NPM
NPM is a package manager for JavaScript that allows developers to easily install and manage dependencies in their projects, serving as a central registry for millions of open-source packages.
Related:
Ledger
- NPM debug and chalk packages compromised (www.aikido.dev)
- Which NPM package has the largest version number? (adamhl.dev)
- Live updates: Shai-hulud, the most dangerous NPM breach in history (www.koi.security)
- NPM package 'debug' v4.4.2 contains malware (social.hackerspace.pl)
- Color NPM Package Compromised (fasterthanli.me)
- Npm packages with over 1b weekly downloads, incl. Chalk, have been compromised. (jdstaerk.substack.com)
- GitHub's plan for a more secure NPM supply chain (github.blog)
- Hackers hijack NPM packages with 2B weekly downloads in supply chain attack (www.bleepingcomputer.com)
- Incident hitting NPM users is likely the biggest supply-chain attack (arstechnica.com)
- Shai-Hulud: The novel self-replicating worm infecting NPM packages (www.sysdig.com)
- More than 40 popular NPM packages compromised (twitter.com)
- Show HN: CVibe – The NPM of Prompts (cvibe.dev)
- How Deno protects against NPM exploits (deno.com)
- GitHub's plan for a more secure NPM supply chain (github.blog)
- Show HN: Silobase – Firebase/Supabase alternative as NPM package (iamsimi.medium.com)
- Our plan for a more secure NPM supply chain (github.blog)
- Lessons from NPM's Security Failures (oneuptime.com)
- NPM Has Become a Russian Roulette (worklifenotes.com)
- NPM Author Qix Compromised via Phishing Email (socket.dev)