home.social

#debugjs — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #debugjs, aggregated by home.social.

  1. TLDR recent #npm supply chain attacks

    🗓️ 26 Aug: #nx packages compromised stealing SSH keys, npm tokens, and .gitconfig files and weaponized AI CLI tools 😱 upload to repo named #S1ngularity
    HackerNews: news.ycombinator.com/item?id=4
    GHSA-cxm3-wv7p-598c: github.com/nrwl/nx/security/ad

    🗓️ 8 Sep: #chalk, #debugjs and other packages by maintainer #qix (junon) compromised. They handled this very transparently 👍️
    See
    HackerNews: news.ycombinator.com/item?id=4
    CVE-2025-59144: github.com/advisories/GHSA-4x4