Microsoft links Mastra AI supply chain attack to North Korean hackers
(bleepingcomputer.com)
1.
2.
AUR Packages Compromised with Infostealer and Rootkit
(news.ycombinator.com)
3.
GitHub announces npm security changes to tackle supply-chain attacks
(bleepingcomputer.com)
4.
New IronWorm malware hits 36 packages in npm supply-chain attack
(bleepingcomputer.com)
6.
Agentic Mfw
(news.ycombinator.com)
7.
Dozens of Red Hat packages backdoored through its official NPM channel
(arstechnica.com)
8.
Dozens of Red Hat packages backdoored through its offical NPM channel
(arstechnica.com)
9.
Red Hat npm packages compromised to steal developer credentials
(bleepingcomputer.com)
10.
11.
Show HN: DepsGuard – one command to harden NPM/pnpm/yarn/bun/uv configs
(news.ycombinator.com)
12.
Malicious npm packages detected across Red Hat Cloud Services
(news.ycombinator.com)
13.
NPM packages from Red Hat have been compromised
(news.ycombinator.com)
14.
NPM packages from RedHat have been compromised
(news.ycombinator.com)
15.
Npm-scan: Modern supply chain security for the npm ecosystem
(news.ycombinator.com)
16.
Claude Code – Everything You Can Configure That the Docs Don't Tell You
(news.ycombinator.com)
17.
18.
You Should Not Update Your Dependencies
(news.ycombinator.com)
19.
20.
GitHub introduces staged publishing and new install-time controls for NPM
(news.ycombinator.com)
21.
Deno 2.8
(news.ycombinator.com)
22.
Uv is fantastic, but its package management UX is a mess
(news.ycombinator.com)
23.
GitHub links repo breach to TanStack npm supply-chain attack
(bleepingcomputer.com)
24.
25.
Grafana breach caused by missed token rotation after TanStack attack
(bleepingcomputer.com)
26.
Dumb ways for an open source project to die
(news.ycombinator.com)
27.
Dumb Ways for an Open Source Project to Die
(news.ycombinator.com)
28.
Show HN: Id-agent – Token efficient UUID alternative for AI agents
(news.ycombinator.com)
29.
New Shai-Hulud malware wave compromises 600 npm packages
(bleepingcomputer.com)
30.
Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
(news.ycombinator.com)
Today's top topics:
prime day
amazon
samsung
android authority
openai
zdnet
apple
oracle
galaxy ai
android 16