home.social

#s1ngularity β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #s1ngularity, aggregated by home.social.

  1. TLDR recent #npm supply chain attacks

    πŸ—“οΈ 26 Aug: #nx packages compromised stealing SSH keys, npm tokens, and .gitconfig files and weaponized AI CLI tools 😱 upload to repo named #S1ngularity
    HackerNews: news.ycombinator.com/item?id=4
    GHSA-cxm3-wv7p-598c: github.com/nrwl/nx/security/ad

    πŸ—“οΈ 8 Sep: #chalk, #debugjs and other packages by maintainer #qix (junon) compromised. They handled this very transparently πŸ‘οΈ
    See
    HackerNews: news.ycombinator.com/item?id=4
    CVE-2025-59144: github.com/advisories/GHSA-4x4