Hackernews posts about Pnpm
- Pnpm temp paths broke lifecycle sockets (github.com)
- PnPUtil Command Line Tool for Driver Packages (learn.microsoft.com)
- Upcoming breaking changes for npm v12 (github.blog)
- Staged publishing and new install-time controls for npm (github.blog)
- New IronWorm malware hits 36 packages in NPM supply-chain attack (www.bleepingcomputer.com)
- Hide Secrets from AI Agents and NPM install using Airgap (sauleau.com)
- NPM attack targets Zapier and security tool browser extensions (opensourcemalware.com)
- I scored 200 blockchain NPM packages for deprecation and hijack risk (chain-audit.netlify.app)
- New IronWorm malware hits 36 packages in NPM supply-chain attack (www.bleepingcomputer.com)
- Miasma NPM Supply Chain Attack: Self-Spreading Worm via Phantom Gyp (www.stepsecurity.io)
- A 176-Package NPM Campaign Built to Beat Your Internal Dependencies (www.sonatype.com)
- New Shai-Hulud malware wave compromises 600 NPM packages (itnerd.blog)
- Multiple mastra NPM packages compromised (github.com)
- Red Hat packages backdoored through its official NPM channel (arstechnica.com)
- GitHub pulls pin on NPM's auto-run scripts (www.theregister.com)
- NPM staged publishing setup with approximately one click per package (lavamoat.github.io)
- >400 AUR Packages Compromised with NPM post-install malware (archlinux.org)