home.social

#npm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #npm, aggregated by home.social.

fetched live
  1. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    Pulse ID: 6a7d499c37a8eebd3c318b8a
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111

  2. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    Pulse ID: 6a7d499c37a8eebd3c318b8a
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111

  3. 🚀 How to Deploy #CapRover on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy CapRover on Ubuntu VPS.
    What is CapRover?
    CapRover is a free, open-source Platform-as-a-Service (PaaS) that ...
    Continued 👉 #certbot #selfhosting #npm #nodejs #ufw #letsencrypt #git #selfhosted

    🚀 How to Deploy CapRover on Ub...

  4. 🚀 How to Deploy #CapRover on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy CapRover on Ubuntu VPS.
    What is CapRover?
    CapRover is a free, open-source Platform-as-a-Service (PaaS) that ...
    Continued 👉 #certbot #selfhosting #npm #nodejs #ufw #letsencrypt #git #selfhosted

    🚀 How to Deploy CapRover on Ub...

  5. 🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)

    This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, ...
    Continued 👉 #npm #selfhosted #clawdbot #selfhosting

    🚀 Deploy Self-Hosted OpenClaw ...

  6. 🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)

    This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, ...
    Continued 👉 #npm #selfhosted #clawdbot #selfhosting

    🚀 Deploy Self-Hosted OpenClaw ...

  7. #dev #web

    Un truc que je n'ai jamais compris / accepté dans l'archi #nodejs #npm c'est la nécessité d'installer dans chacun de ses projets des dépendances de librairies qui peuvent / doivent être partagé, genre #eslint (linter) ou #esbuild (packaging).

    Je ne développe pas sinon je vais m'énerver (si votre projet ne peut fonctionner qu'avec une version précise de eslint ou esbuild, désolé mais c'est que vous avez mal construit votre projet au départ !)

    (1/2)

  8. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  9. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  10. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  11. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  12. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.

    Pulse ID: 6a7b39b0e4765559a182c347
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:03:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault

  13. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.

    Pulse ID: 6a7b39b0e4765559a182c347
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:03:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault

  14. Source maps or not? @43081j and @manniL explain when npm packages should ship source maps and when they just bloat installs. Publishing them grew the change-case package from 7.2 to 22.7KB, while dropping them cut magic-string from 241 to 155KB. Source maps only pay off when the published code is lossy: minified output or compiled syntaxes like Vue SFCs. Ship readable, unminified library code, or host sources remotely with sourceRoot. #npm

    e18e.dev/blog/source-maps-or-n

  15. Source maps or not? @43081j and @manniL explain when npm packages should ship source maps and when they just bloat installs. Publishing them grew the change-case package from 7.2 to 22.7KB, while dropping them cut magic-string from 241 to 155KB. Source maps only pay off when the published code is lossy: minified output or compiled syntaxes like Vue SFCs. Ship readable, unminified library code, or host sources remotely with sourceRoot. #npm

    e18e.dev/blog/source-maps-or-n

  16. Нужны ли карты кода? Джеймс Гарбутт и Алекс Лихтер объясняют, когда npm-пакетам стоит их публиковать, а когда они лишь раздувают вес. Из-за них пакет change-case вырос с 7,2 КБ до 22,7 КБ, а magic-string без них уменьшился с 241 КБ до 155 КБ. Они оправданы, только если опубликованный код теряет информацию: минифицированный вывод или синтаксис вроде Vue SFC. Лучше публиковать читаемый код без минификации или хранить исходники удалённо через sourceRoot. #npm #performance

    e18e.dev/blog/source-maps-or-n

  17. Нужны ли карты кода? Джеймс Гарбутт и Алекс Лихтер объясняют, когда npm-пакетам стоит их публиковать, а когда они лишь раздувают вес. Из-за них пакет change-case вырос с 7,2 КБ до 22,7 КБ, а magic-string без них уменьшился с 241 КБ до 155 КБ. Они оправданы, только если опубликованный код теряет информацию: минифицированный вывод или синтаксис вроде Vue SFC. Лучше публиковать читаемый код без минификации или хранить исходники удалённо через sourceRoot. #npm #performance

    e18e.dev/blog/source-maps-or-n

  18. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    Pulse ID: 6a7aa9831dfdf9b50bc371c2
    Pulse Link: otx.alienvault.com/pulse/6a7aa
    Pulse Author: Tr1sa111
    Created: 2026-08-11 04:48:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Russia #bot #Tr1sa111

  19. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    Pulse ID: 6a7aa9831dfdf9b50bc371c2
    Pulse Link: otx.alienvault.com/pulse/6a7aa
    Pulse Author: Tr1sa111
    Created: 2026-08-11 04:48:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Russia #bot #Tr1sa111

  20. CVE-2026-48161 | CRITICAL: dai-shi react18-use had malicious postinstall script — RCE on dev machines via npm install. Not in npm registry, but local checkouts may be compromised. Rotate creds & reimage if affected. radar.offseq.com/threat/cve-20 #OffSeq #SupplyChain #CVE #npm #infosec

  21. Reward: You've received a Participation Certificate (Compromised Edition). It is non-transferable. Your credentials, however, were.

    #SupplyChainAttack #Malware #npm #SoftwareSecurity #CredentialTheft #WormPropagation (3/3)

  22. Reward: You've received a Participation Certificate (Compromised Edition). It is non-transferable. Your credentials, however, were.

    #SupplyChainAttack #Malware #npm #SoftwareSecurity #CredentialTheft #WormPropagation (3/3)

  23. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  24. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  25. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  26. Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

    A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

    Pulse ID: 6a76515e8fbfccabf4dbb65b
    Pulse Link: otx.alienvault.com/pulse/6a765
    Pulse Author: AlienVault
    Created: 2026-08-07 21:42:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault

  27. Inside a Self-Propagating npm Worm

    Pulse ID: 6a7951d7e4e9679263bf13be
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111

  28. Inside a Self-Propagating npm Worm

    Pulse ID: 6a7951d7e4e9679263bf13be
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111

  29. 🚨🐛 SIGINT // Cybersecurity Watch — 2026-08-10
    Nearly 800 malicious npm packages caught delivering a cross-platform RAT & infostealer (WEL1DROPPER), hitting Windows, macOS, and Linux devs.
    thehackernews.com/2026/08/near

  30. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #selfhosting #cmsapps #npm #postgresql #contentmanagement #letsencrypt #nodejs #vpsguide #installguide #selfhosted #opensource

  31. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #selfhosting #cmsapps #npm #postgresql #contentmanagement #letsencrypt #nodejs #vpsguide #installguide #selfhosted #opensource

  32. pnpm released another project: pnpr, an npm registry.

    It is proprietary.

    In my opinion mixing proprietary and open source code in one project is a recipe for disaster and I will try to avoid such projects when I can.

    Am I being overzealous?

    #JavaScript #npm #pnpm

  33. pnpm released another project: pnpr, an npm registry.

    It is proprietary.

    In my opinion mixing proprietary and open source code in one project is a recipe for disaster and I will try to avoid such projects when I can.

    Am I being overzealous?

    #JavaScript #npm #pnpm

  34. 🚀 How to Deploy #Phanpy on #AlmaLinux #VPS

    This article provides a guide demonstrating how to deploy Phanpy on AlmaLinux VPS.
    What is Phanpy?
    Phanpy is a modern alternative web frontend for #Mastodon and compatible #Fediverse platforms. It is designed as a minimalistic, ultra-fast, privacy-conscious #social client that lets users browse, post, reply, boost, and manage Mastodon accounts ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosted #selfhosting #firewalld #letsencrypt #fail2ban #npm

  35. 🚀 How to Deploy #Phanpy on #AlmaLinux #VPS

    This article provides a guide demonstrating how to deploy Phanpy on AlmaLinux VPS.
    What is Phanpy?
    Phanpy is a modern alternative web frontend for #Mastodon and compatible #Fediverse platforms. It is designed as a minimalistic, ultra-fast, privacy-conscious #social client that lets users browse, post, reply, boost, and manage Mastodon accounts ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosted #selfhosting #firewalld #letsencrypt #fail2ban #npm

  36. Der GitHub-Account des Maintainers der Key-Value-Datenbank #keyv wurde kompromittiert Durch die Shai-Hulud-Lieferkettenattacke sind über 440 #npm-Pakete betroffen mit rund 2 Milliarden Downloads monatlich Der Schadcode startet automatisch bei Installation und sucht nach Zugangsdaten heise.de/news/Lieferketten-Ang

  37. Der GitHub-Account des Maintainers der Key-Value-Datenbank #keyv wurde kompromittiert Durch die Shai-Hulud-Lieferkettenattacke sind über 440 #npm-Pakete betroffen mit rund 2 Milliarden Downloads monatlich Der Schadcode startet automatisch bei Installation und sucht nach Zugangsdaten heise.de/news/Lieferketten-Ang

  38. 🚀 How to Deploy #CapRover on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy CapRover on Ubuntu VPS.
    What is CapRover?
    CapRover is a free, open-source Platform-as-a-Service (PaaS) that ...
    Continued 👉 #letsencrypt #npm #certbot #ufw #selfhosted #git #nodejs #selfhosting

    🚀 How to Deploy CapRover on Ub...

  39. 🚀 How to Deploy #CapRover on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy CapRover on Ubuntu VPS.
    What is CapRover?
    CapRover is a free, open-source Platform-as-a-Service (PaaS) that ...
    Continued 👉 #letsencrypt #npm #certbot #ufw #selfhosted #git #nodejs #selfhosting

    🚀 How to Deploy CapRover on Ub...

  40. 🚀 Deploy Self-Hosted #OpenClaw on #VPS (3 Minute Quick-Start Guide 🤖)

    This article provides a quick, yet thorough step-by-step guide to deploy self-hosted OpenClaw on VPS servers. A lot of users have been deploying directly to Mac Minis, but we'd like to present another, radically different clawd deployment strategy. In this guide, we will deploy OpenClaw on Linux VPS-specifically, #Debian VPS.
    What is OpenClaw? ...
    Continued 👉 blog.radwebhosting.com/deploy- #clawdbot #selfhosting #selfhosted #npm

  41. ChainDrop npm Supply Chain Worm Attack Target Developers and CI/CD Environments

    Pulse ID: 6a76817228e67b24b4fb3e61
    Pulse Link: otx.alienvault.com/pulse/6a768
    Pulse Author: cryptocti
    Created: 2026-08-08 01:08:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #developers #cryptocti

  42. ChainDrop npm Supply Chain Worm Attack Target Developers and CI/CD Environments

    Pulse ID: 6a76817228e67b24b4fb3e61
    Pulse Link: otx.alienvault.com/pulse/6a768
    Pulse Author: cryptocti
    Created: 2026-08-08 01:08:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #developers #cryptocti

  43. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #vpsguide #contentmanagement #nodejs #opensource #cmsapps #npm #selfhosting #selfhosted #letsencrypt #postgresql #installguide

  44. How to Install #Directus on #AlmaLinux #VPS

    Here's a step-by-step guide detailing how to install Directus on AlmaLinux VPS.
    What is Directus?
    Directus is an open-source #headless #CMS and data platform that allows you to manage and interact with your database through a RESTful API or GraphQL API. It provides a modern, ...
    Continued 👉 blog.radwebhosting.com/install #vpsguide #contentmanagement #nodejs #opensource #cmsapps #npm #selfhosting #selfhosted #letsencrypt #postgresql #installguide

  45. Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

    Indicators extracted from public reporting. Source: opensourcemalware.com/blog/rus

    Pulse ID: 6a763860fd9d05bceee48cc7
    Pulse Link: otx.alienvault.com/pulse/6a763
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 19:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Russia #bot #CyberHunter_NL

  46. Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

    Indicators extracted from public reporting. Source: opensourcemalware.com/blog/rus

    Pulse ID: 6a763860fd9d05bceee48cc7
    Pulse Link: otx.alienvault.com/pulse/6a763
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 19:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Russia #bot #CyberHunter_NL

  47. I don't develop using #npm, and I guess this happens with #pypi and #nuget as well.
    What's the answer? Only install stuff completely manually? Don't store credentials on your dev PCs, only in your e.g. smartphone and enter them manually? Let humans manually verify each upload to package registries? /s

  48. У нас есть для вас пакет! Как LLM придумывают несуществующие зависимости

    Что произойдет, если большая языковая модель (LLM) добавит в код пакет, которого никогда не существовало? Разработчик может принять рекомендацию за корректную, а злоумышленник – опубликовать под придуманным именем вредоносный пакет. Тогда ошибка модели превращается в возможность атаки на цепочку поставки. Перед вами обзор исследования We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs . Авторы проверили 16 моделей, сгенерировали 576 000 образцов кода на Python и JavaScript и изучили, как часто в ответах появляются несуществующие пакеты. Их работу отметили наградой “Distinguished Paper Award” на конференции USENIX Security 2025.

    habr.com/ru/companies/codescor

    #галлюцинации_пакетов #llm #генерация_кода #цепочка_поставки_по #подмена_пакетов #package_confusion #pypi #npm #безопасность_зависимостей #usenix_security