#npm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #npm, aggregated by home.social.
-
How to Install #Directus on #AlmaLinux #VPS
Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
What is Directus?
Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
Continued 👉 https://blog.radwebhosting.com/install-directus-on-almalinux-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #contentmanagement #opensource #selfhosting #installguide #nodejs #npm #letsencrypt #vpsguide #postgresql #cmsapps #selfhosted -
How to Install #Directus on #AlmaLinux #VPS
Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
What is Directus?
Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
Continued 👉 https://blog.radwebhosting.com/install-directus-on-almalinux-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #contentmanagement #opensource #selfhosting #installguide #nodejs #npm #letsencrypt #vpsguide #postgresql #cmsapps #selfhosted -
How to Install #Directus on #AlmaLinux #VPS
Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
What is Directus?
Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
Continued 👉 https://blog.radwebhosting.com/install-directus-on-almalinux-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #contentmanagement #opensource #selfhosting #installguide #nodejs #npm #letsencrypt #vpsguide #postgresql #cmsapps #selfhosted -
this vibe coded PR with 1,000,000+ additions is just open-source ransomware with prettier commit messages.
shoutout to the brave soul reviewing:
"LGTM" after skimming 14 lines… 🤡
uninstalling immediately!
-
this vibe coded PR with 1,000,000+ additions is just open-source ransomware with prettier commit messages.
shoutout to the brave soul reviewing:
"LGTM" after skimming 14 lines… 🤡
uninstalling immediately!
-
this vibe coded PR with 1,000,000+ additions is just open-source ransomware with prettier commit messages.
shoutout to the brave soul reviewing:
"LGTM" after skimming 14 lines… 🤡
uninstalling immediately!
-
This timeline tab on npmx.dev shows good & bad changes to the package over time. :)
https://npmx.dev/package-timeline/@ayo-run/status-indicator/v/2.1.1
-
This timeline tab on npmx.dev shows good & bad changes to the package over time. :)
https://npmx.dev/package-timeline/@ayo-run/status-indicator/v/2.1.1
-
This timeline tab on npmx.dev shows good & bad changes to the package over time. :)
https://npmx.dev/package-timeline/@ayo-run/status-indicator/v/2.1.1
-
This timeline tab on npmx.dev shows good & bad changes to the package over time. :)
https://npmx.dev/package-timeline/@ayo-run/status-indicator/v/2.1.1
-
This timeline tab on npmx.dev shows good & bad changes to the package over time. :)
https://npmx.dev/package-timeline/@ayo-run/status-indicator/v/2.1.1
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- https://github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
- https://github.com/npm/cli/issues/8464 (regression since 2025) -
Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- https://github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
- https://github.com/npm/cli/issues/8464 (regression since 2025) -
Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- https://github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
- https://github.com/npm/cli/issues/8464 (regression since 2025) -
Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- https://github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
- https://github.com/npm/cli/issues/8464 (regression since 2025) -
Been getting these random #npm issues lately 😕
Scenario: dependency has optional peer dep that installs pre-built binaries based on current OS. I npm install it on macOS, it gets the macOS binaries & put it as non-optional dep in package-lock.json. CI runs on Linux, it got confused & failed installation. And npm ci doesn't skip incompatible peer deps.
Relevant issues:
- https://github.com/npm/cli/issues/7750 (2024, closed, continued in other issues/PRs)
- https://github.com/npm/cli/issues/8464 (regression since 2025) -
#Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?eicker.news #tech #media #news
-
#Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?eicker.news #tech #media #news
-
#Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?eicker.news #tech #media #news
-
#Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?eicker.news #tech #media #news
-
#Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?eicker.news #tech #media #news
-
Malware Worm Targets npm, PyPi in Mass Supply-Chain Attack
A self-spreading worm, dubbed Mini Shai-Hulud, has infected over 170 packages with nearly 180 million weekly downloads, posing a massive threat to the software supply chain. This highly contagious malware has been open-sourced, making it easier for others to exploit and escalate the attack.
-
New.
Picus: Mini Shai-Hulud: The npm Supply Chain Worm Explained https://www.picussecurity.com/resource/blog/mini-shai-hulud-the-npm-supply-chain-worm-explained
Rapid7: When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise/ @Rapid7Official
Published yesterday:
Sophos: Operating inside the lethal trifecta: Blast radius reduction in AI agent deployments https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments @SophosXOps #infosec #threatresearch #npm #Teams #Microsoft #bot
-
New.
Picus: Mini Shai-Hulud: The npm Supply Chain Worm Explained https://www.picussecurity.com/resource/blog/mini-shai-hulud-the-npm-supply-chain-worm-explained
Rapid7: When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise/ @Rapid7Official
Published yesterday:
Sophos: Operating inside the lethal trifecta: Blast radius reduction in AI agent deployments https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments @SophosXOps #infosec #threatresearch #npm #Teams #Microsoft #bot
-
New.
Picus: Mini Shai-Hulud: The npm Supply Chain Worm Explained https://www.picussecurity.com/resource/blog/mini-shai-hulud-the-npm-supply-chain-worm-explained
Rapid7: When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise/ @Rapid7Official
Published yesterday:
Sophos: Operating inside the lethal trifecta: Blast radius reduction in AI agent deployments https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments @SophosXOps #infosec #threatresearch #npm #Teams #Microsoft #bot
-
New.
Picus: Mini Shai-Hulud: The npm Supply Chain Worm Explained https://www.picussecurity.com/resource/blog/mini-shai-hulud-the-npm-supply-chain-worm-explained
Rapid7: When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise/ @Rapid7Official
Published yesterday:
Sophos: Operating inside the lethal trifecta: Blast radius reduction in AI agent deployments https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments @SophosXOps #infosec #threatresearch #npm #Teams #Microsoft #bot
-
New.
Picus: Mini Shai-Hulud: The npm Supply Chain Worm Explained https://www.picussecurity.com/resource/blog/mini-shai-hulud-the-npm-supply-chain-worm-explained
Rapid7: When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise/ @Rapid7Official
Published yesterday:
Sophos: Operating inside the lethal trifecta: Blast radius reduction in AI agent deployments https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments @SophosXOps #infosec #threatresearch #npm #Teams #Microsoft #bot
-
Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.
Read: https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/
-
Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.
Read: https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/
-
Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.
Read: https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/
-
Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.
Read: https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/
-
Research reveals that #TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.
Read: https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/
-
TanStack npm Packages Compromised in Ongoing Supply-Chain Attack
Pulse ID: 6a040869301ab23a12b403da
Pulse Link: https://otx.alienvault.com/pulse/6a040869301ab23a12b403da
Pulse Author: Tr1sa111
Created: 2026-05-13 05:13:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111
-
TanStack npm Packages Compromised in Ongoing Supply-Chain Attack
Pulse ID: 6a040869301ab23a12b403da
Pulse Link: https://otx.alienvault.com/pulse/6a040869301ab23a12b403da
Pulse Author: Tr1sa111
Created: 2026-05-13 05:13:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111
-
TanStack npm Packages Compromised in Ongoing Supply-Chain Attack
Pulse ID: 6a040869301ab23a12b403da
Pulse Link: https://otx.alienvault.com/pulse/6a040869301ab23a12b403da
Pulse Author: Tr1sa111
Created: 2026-05-13 05:13:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111
-
TanStack npm Packages Compromised in Ongoing Supply-Chain Attack
Pulse ID: 6a040869301ab23a12b403da
Pulse Link: https://otx.alienvault.com/pulse/6a040869301ab23a12b403da
Pulse Author: Tr1sa111
Created: 2026-05-13 05:13:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111
-
TanStack npm Packages Compromised in Ongoing Supply-Chain Attack
Pulse ID: 6a040869301ab23a12b403da
Pulse Link: https://otx.alienvault.com/pulse/6a040869301ab23a12b403da
Pulse Author: Tr1sa111
Created: 2026-05-13 05:13:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #bot #Tr1sa111
-
🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)
This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, but we'd like to present another, radically different clawd deployment strategy. In this guide, we will deploy OpenClaw on Linux VPS-specifically, #Debian VPS.
What is ...
Continued 👉 https://blog.radwebhosting.com/deploy-self-hosted-openclaw-on-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #selfhosting #clawdbot #selfhosted #npm -
🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)
This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, but we'd like to present another, radically different clawd deployment strategy. In this guide, we will deploy OpenClaw on Linux VPS-specifically, #Debian VPS.
What is ...
Continued 👉 https://blog.radwebhosting.com/deploy-self-hosted-openclaw-on-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #selfhosting #clawdbot #selfhosted #npm -
🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)
This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, but we'd like to present another, radically different clawd deployment strategy. In this guide, we will deploy OpenClaw on Linux VPS-specifically, #Debian VPS.
What is ...
Continued 👉 https://blog.radwebhosting.com/deploy-self-hosted-openclaw-on-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #selfhosting #clawdbot #selfhosted #npm -
How to Install #Directus on #AlmaLinux #VPS
Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
What is Directus?
Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
Continued 👉 https://blog.radwebhosting.com/install-directus-on-almalinux-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #nodejs #cmsapps #opensource #installguide #contentmanagement #letsencrypt #npm #selfhosted #postgresql #selfhosting #vpsguide