Malicious NPM packages fetch infostealer for Windows, Linux, macOS
(bleepingcomputer.com)
61.
62.
NPM flooded with malicious packages downloaded more than 86,000 times
(arstechnica.com)
63.
PhantomRaven attack floods npm with credential-stealing packages
(bleepingcomputer.com)
64.
React Flow, open source libraries for node-based UIs with React or Svelte
(news.ycombinator.com)
65.
PyOCI – Publish and install private Python packages using OCI/Docker registries
(news.ycombinator.com)
66.
Cleaning house in Nx monorepo, how i removed unused deps safely
(news.ycombinator.com)
67.
If all the world were a monorepo
(news.ycombinator.com)
68.
Tinycolor supply chain attack post-mortem
(news.ycombinator.com)
69.
CrowdStrike Infested With "Self-Replicating Worms"
(futurism.com)
70.
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
(news.ycombinator.com)
71.
Live Updates: Shai-Hulud, the Most Dangerous NPM Breach in History
(news.ycombinator.com)
72.
Self-propagating supply chain attack hits 187 npm packages
(bleepingcomputer.com)
73.
Self-Replicating Worm Hits 180+ Software Packages
(krebsonsecurity.com)
74.
Self Propagating NPM Malware Compromises over 40 Packages
(news.ycombinator.com)
75.
Which NPM package has the largest version number?
(news.ycombinator.com)
76.
Hackers left empty-handed after massive NPM supply-chain attack
(bleepingcomputer.com)
78.
79.
80.
Nuclear: Desktop music player focused on streaming from free sources
(news.ycombinator.com)
81.
Show HN: Simple modenized .NET NuGet server reached RC
(news.ycombinator.com)
82.
Much of the World Stops Sending Mail to U.S.
(gizmodo.com)
83.
84.
Debian 13 "Trixie"
(news.ycombinator.com)
85.
Fake WhatsApp developer libraries hide destructive data-wiping code
(bleepingcomputer.com)
86.
Trump Ends Tariff Exemption for Small Packages
(wired.com)
87.
Supply-chain attacks on open source software are getting out of hand
(arstechnica.com)
88.
Open source repositories are seeing a rash of supply-chain attacks
(arstechnica.com)
89.
Hackers breach Toptal GitHub account, publish malicious npm packages
(bleepingcomputer.com)
90.
npm 'accidentally' removes Stylus package, breaks builds and pipelines
(bleepingcomputer.com)