The Three Pillars of JavaScript Bloat
(news.ycombinator.com)
91.
92.
93.
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
(bleepingcomputer.com)
94.
GlassWorm Malware Evolves to Hide in Dependencies
(darkreading.com)
95.
Glassworm is back: A new wave of invisible Unicode attacks hits repositories
(news.ycombinator.com)
96.
Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
(news.ycombinator.com)
97.
98.
99.
Vite 8.0 Is Out
(news.ycombinator.com)
100.
Show HN: Rudel – Claude Code Session Analytics
(news.ycombinator.com)
101.
Secure Secrets Management for Cursor Cloud Agents
(news.ycombinator.com)
102.
If It Quacks Like a Package Manager
(news.ycombinator.com)
103.
TypeScript 6.0 RC
(news.ycombinator.com)
104.
A GitHub Issue Title Compromised 4k Developer Machines
(news.ycombinator.com)
105.
Google Workspace CLI
(news.ycombinator.com)
106.
Show HN: Gapless.js – gapless web audio playback
(news.ycombinator.com)
107.
A rabbit hole in 5 commits
(news.ycombinator.com)
108.
LLM=True
(news.ycombinator.com)
109.
Pi – A minimal terminal coding harness
(news.ycombinator.com)
110.
Pi – a minimal terminal coding harness
(news.ycombinator.com)
111.
I'm helping my dog vibe code games
(news.ycombinator.com)
112.
NPM install is stealing your passwords – I built a tool to catch it
(news.ycombinator.com)
113.
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
(darkreading.com)
114.
I Don't Like Magic
(news.ycombinator.com)
115.
NPMX – a fast, modern browser for the NPM registry
(news.ycombinator.com)
116.
Two new RSC protocol vulnerabilities uncovered
(news.ycombinator.com)
117.
Show HN: Safe-NPM – only install packages that are +90 days old
(news.ycombinator.com)
118.
NPM flooded with malicious packages downloaded more than 86k times
(news.ycombinator.com)
119.
Malicious NPM packages fetch infostealer for Windows, Linux, macOS
(bleepingcomputer.com)
120.
NPM flooded with malicious packages downloaded more than 86,000 times
(arstechnica.com)