home.social

#npm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #npm, aggregated by home.social.

  1. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #contentmanagement #opensource #selfhosting #installguide #nodejs #npm #letsencrypt #vpsguide #postgresql #cmsapps #selfhosted

  2. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #contentmanagement #opensource #selfhosting #installguide #nodejs #npm #letsencrypt #vpsguide #postgresql #cmsapps #selfhosted

  3. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #contentmanagement #opensource #selfhosting #installguide #nodejs #npm #letsencrypt #vpsguide #postgresql #cmsapps #selfhosted

  4. this vibe coded PR with 1,000,000+ additions is just open-source ransomware with prettier commit messages.

    shoutout to the brave soul reviewing:

    "LGTM" after skimming 14 lines… 🤡

    uninstalling immediately!

    github.com/oven-sh/bun/pull/30

    #npm #yarn #pnpm #bun #deno #js #javascript #typescript

  5. this vibe coded PR with 1,000,000+ additions is just open-source ransomware with prettier commit messages.

    shoutout to the brave soul reviewing:

    "LGTM" after skimming 14 lines… 🤡

    uninstalling immediately!

    github.com/oven-sh/bun/pull/30

    #npm #yarn #pnpm #bun #deno #js #javascript #typescript

  6. this vibe coded PR with 1,000,000+ additions is just open-source ransomware with prettier commit messages.

    shoutout to the brave soul reviewing:

    "LGTM" after skimming 14 lines… 🤡

    uninstalling immediately!

    github.com/oven-sh/bun/pull/30

    #npm #yarn #pnpm #bun #deno #js #javascript #typescript

  7. Been getting these random #npm issues lately 😕

    Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.

    Relevant issues:
    - github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
    - github.com/npm/cli/issues/8464 (regression since 2025)

  8. Been getting these random #npm issues lately 😕

    Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.

    Relevant issues:
    - github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
    - github.com/npm/cli/issues/8464 (regression since 2025)

  9. Been getting these random #npm issues lately 😕

    Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.

    Relevant issues:
    - github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
    - github.com/npm/cli/issues/8464 (regression since 2025)

  10. Been getting these random #npm issues lately 😕

    Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.

    Relevant issues:
    - github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
    - github.com/npm/cli/issues/8464 (regression since 2025)

  11. Been getting these random #npm issues lately 😕

    Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.

    Relevant issues:
    - github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
    - github.com/npm/cli/issues/8464 (regression since 2025)

  12. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  13. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  14. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  15. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  16. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  17. Malware Worm Targets npm, PyPi in Mass Supply-Chain Attack

    A self-spreading worm, dubbed Mini Shai-Hulud, has infected over 170 packages with nearly 180 million weekly downloads, posing a massive threat to the software supply chain. This highly contagious malware has been open-sourced, making it easier for others to exploit and escalate the attack.

    osintsights.com/malware-worm-t

    #SupplyChain #MalwareOperations #Npm #Pypi #Shaihulud

  18. Research reveals that hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

  19. Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

    #CyberSecurity #Malware #ShaiHulud #CyberAttack #npm

  20. Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

    #CyberSecurity #Malware #ShaiHulud #CyberAttack #npm

  21. Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

    #CyberSecurity #Malware #ShaiHulud #CyberAttack #npm

  22. Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

    #CyberSecurity #Malware #ShaiHulud #CyberAttack #npm

  23. TanStack npm Packages Compromised in Ongoing Supply-Chain Attack

    Pulse ID: 6a040869301ab23a12b403da
    Pulse Link: otx.alienvault.com/pulse/6a040
    Pulse Author: Tr1sa111
    Created: 2026-05-13 05:13:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111

  24. TanStack npm Packages Compromised in Ongoing Supply-Chain Attack

    Pulse ID: 6a040869301ab23a12b403da
    Pulse Link: otx.alienvault.com/pulse/6a040
    Pulse Author: Tr1sa111
    Created: 2026-05-13 05:13:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111

  25. TanStack npm Packages Compromised in Ongoing Supply-Chain Attack

    Pulse ID: 6a040869301ab23a12b403da
    Pulse Link: otx.alienvault.com/pulse/6a040
    Pulse Author: Tr1sa111
    Created: 2026-05-13 05:13:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111

  26. TanStack npm Packages Compromised in Ongoing Supply-Chain Attack

    Pulse ID: 6a040869301ab23a12b403da
    Pulse Link: otx.alienvault.com/pulse/6a040
    Pulse Author: Tr1sa111
    Created: 2026-05-13 05:13:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111

  27. TanStack npm Packages Compromised in Ongoing Supply-Chain Attack

    Pulse ID: 6a040869301ab23a12b403da
    Pulse Link: otx.alienvault.com/pulse/6a040
    Pulse Author: Tr1sa111
    Created: 2026-05-13 05:13:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111

  28. 🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)

    This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, but we'd like to present another, radically different clawd deployment strategy. In this guide, we will deploy OpenClaw on Linux VPS-specifically, #Debian VPS.
    What is ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosting #clawdbot #selfhosted #npm

  29. 🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)

    This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, but we'd like to present another, radically different clawd deployment strategy. In this guide, we will deploy OpenClaw on Linux VPS-specifically, #Debian VPS.
    What is ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosting #clawdbot #selfhosted #npm

  30. 🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)

    This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, but we'd like to present another, radically different clawd deployment strategy. In this guide, we will deploy OpenClaw on Linux VPS-specifically, #Debian VPS.
    What is ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosting #clawdbot #selfhosted #npm

  31. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #nodejs #cmsapps #opensource #installguide #contentmanagement #letsencrypt #npm #selfhosted #postgresql #selfhosting #vpsguide