#npmsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #npmsecurity, aggregated by home.social.
-
@hacksilon PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package.
#supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc
-
😂 Oh, look! NPM's latest security "innovation" is just a fancy way to make us wait longer for our bugs! ⏳ Apparently, the new tactic is to timegate updates like a bad sequel, but spoiler alert: it's about as effective as a #chocolate teapot! 🍫☕
https://blog.outv.im/2026/npm-cooldown-security-theater/ #NPMsecurity #timegating #softwareupdates #techhumor #teapot #HackerNews #ngated -
Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/
#HackerNews #MiniShaiHulud #npmSecurity #CyberThreats #PackageCompromise #SoftwareVulnerability
-
🔥🚀 Oh, rejoice! Another day, another hack—this time, Bitwarden's CLI couldn't dodge a bullet in the #Checkmarx supply chain campaign. Thank goodness for Socket Research Team, because without them, we'd never know which npm package will ruin our day next! 🙄🔒💥
https://socket.dev/blog/bitwarden-cli-compromised #Bitwarden #SupplyChain #SocketResearch #npmSecurity #HackNews #HackerNews #ngated -
Wow, who knew that downloading a seemingly innocent NPM package could lead to your WhatsApp messages being harvested like crops in FarmVille? 🌾📱 Clearly, 56,000 people learned the hard way that trusting random code on the internet is like expecting your cat to respect your personal space. 🐱💻
https://www.koi.ai/blog/npm-package-with-56k-downloads-malware-stealing-whatsapp-messages #NPMsecurity #WhatsAppprivacy #codingrisks #trustissues #cybersecurity #HackerNews #ngated -
A simple typo could be the door hackers use to break in. Malicious npm packages with nearly identical names are now tricking developers to steal credentials and data. Curious how a spelling error can lead to major breaches?
#npmsecurity
#typosquatting
#supplychainattack
#malware
#infostealer -
Npm packages are under siege. How did attackers use trusted developer tools to weave a self-spreading threat across the open-source community? Find out how the Shai-Hulud attack could change software security forever.
#shaihuludattack
#softwaresupplychain
#npmsecurity
#cyberthreats
#opensourcevulnerabilities -
Although npm has been compromised, your site is probably not affected. Read this article to help you keep calm and avoid panicking, while still keeping an eye on web security:
https://metadrop.net/en/articles/npm-compromised-you-are-probably-not-risk
-
Great analysis of the malware distributed with the esling-config-prettier NPM package compromise on Friday: https://c-b.io/2025-07-20+-+Install+Linters%2C+Get+Malware+-+DevSecOps+Speedrun+Edition
By c-b.io on Bluesky / cyb3rjerry on Twitter :D
#malwareanalysis #reverseengineering #infosec #npm #npmsecurity #malware #reversing
-
A breach in 16 popular NPM packages rocked the JavaScript world—malicious code gave attackers a backdoor right into trusted projects. How secure are your dependencies?
#supplychainattack
#npmsecurity
#javascript
#cybersecurity
#malware -
The rise of malicious npm packages—like `xlsx-to-json-lh` mimicking `xlsx-to-json-lc`—raises urgent questions. Should npm enforce name uniqueness and vetting to stop supply chain attacks, or risk stifling its open ecosystem? #NpmSecurity #OpenSourceRisks #Cybersecurity