Hackernews posts about NPMX
- Show HN: A Bluesky client for PICO-8 (picosky.vinnymac.dev)
- Upcoming breaking changes for npm v12 (github.blog)
- New IronWorm malware hits 36 packages in NPM supply-chain attack (www.bleepingcomputer.com)
- Hide Secrets from AI Agents and NPM install using Airgap (sauleau.com)
- NPM attack targets Zapier and security tool browser extensions (opensourcemalware.com)
- I scored 200 blockchain NPM packages for deprecation and hijack risk (chain-audit.netlify.app)
- New IronWorm malware hits 36 packages in NPM supply-chain attack (www.bleepingcomputer.com)
- Miasma NPM Supply Chain Attack: Self-Spreading Worm via Phantom Gyp (www.stepsecurity.io)
- A 176-Package NPM Campaign Built to Beat Your Internal Dependencies (www.sonatype.com)
- New Shai-Hulud malware wave compromises 600 NPM packages (itnerd.blog)
- Multiple mastra NPM packages compromised (github.com)
- Red Hat packages backdoored through its official NPM channel (arstechnica.com)
- GitHub pulls pin on NPM's auto-run scripts (www.theregister.com)
- NPM staged publishing setup with approximately one click per package (lavamoat.github.io)
- >400 AUR Packages Compromised with NPM post-install malware (archlinux.org)
- Someone at NPM needs see this – to stop the madness (www.youtube.com)
- Update on supply chain compromise of Red Hat cloud-services NPM packages (access.redhat.com)
- Show HN: MCP Registry – NPM-style install for MCP servers (mcp-registry-dh5.pages.dev)
- Red Hat packages backdoored through its offical NPM channel (arstechnica.com)
- How to Evaluate an NPM Package – 2026 Edition (blog.gaborkoos.com)