home.social

#npmpackages — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #npmpackages, aggregated by home.social.

fetched live
  1. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  2. How-To Geek: NPM packages are infected with malware, again. “It should be noted that the issue actually seems to spill over into the Maven ecosystem. Researchers observed that the malicious payload was present in org.mvnpm:posthog-node, a Maven artifact automatically generated from npm packages. This confirms that the automated bridging of software ecosystems can inadvertently bridge security […]

    https://rbfirehose.com/2025/11/26/how-to-geek-npm-packages-are-infected-with-malware-again/

  3. 🐛 Oh joy, another thrilling episode of "Whack-a-Mole: Software Edition," where 300+ NPM packages show us that open source security is an oxymoron! 🎉 #HelixGuard struts in with their clipboard and magnifying glass, ready to save the day—right after the damage is done. 🔍📝
    helixguard.ai/blog/malicious-s #openSourceSecurity #NPMpackages #softwareVulnerabilities #cybersecurity #HackerNews #ngated

  4. There's a new release for bgg-client, my JavaScript library for making it easier to use the BoardGameGeek API in your apps!

    I've added validation, and have done a lot of work behind the scenes to ensure data integrity, more consistent typing, and better type-safety.

    npmjs.com/package/bgg-client

    #webdev #javascript #typescript #NPMPackages #boardgames

  5. Just dropped a new release of bgg-client with a breaking change:

    An API key from BoardGameGeek is now required.

    npmjs.com/package/bgg-client

    #webdev #javascript #NPMPackages #boardgames

  6. 🎩✨ "Let the little guys in," they say, as if trusting your bank account and ChatGPT with any random npm package is the next big thing! 🤡 Here’s a revolutionary thought: instead of locking down data, let’s just open the floodgates and watch as the personalized web devolves into majestic chaos. 🚀🌐
    arjun.md/little-guys #OpenData #WebChaos #npmPackages #TrustInTech #PersonalizedWeb #HackerNews #ngated