Massive ChainDrop npm supply-chain attack infects hundreds of packages
(bleepingcomputer.com)
1.
2.
Keyv and friends compromised in active Shai-Hulud supply chain attack
(news.ycombinator.com)
3.
Decimen Optical Transfer: fountain-coded QR file transfer
(news.ycombinator.com)
4.
CodePen 2.0
(news.ycombinator.com)
5.
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
(bleepingcomputer.com)
6.
Show HN: A local merge queue for parallel Claude Code agents
(news.ycombinator.com)
7.
Disrupting supply chain attacks on NPM and GitHub Actions
(news.ycombinator.com)
8.
98.css
(news.ycombinator.com)
9.
Tangleflow: Converts GitHub Actions workflows to tangled workflows and back
(news.ycombinator.com)
10.
Zero-dependency streaming tar parser and writer for JavaScript
(news.ycombinator.com)
11.
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
(bleepingcomputer.com)
12.
Show HN: CLI that helps AI agents avoid vulnerable dependencies
(news.ycombinator.com)
13.
Show HN: Claudoro, Pomodoro timer embedded in the Claude Code statusline
(news.ycombinator.com)
14.
Show HN: Nub – A Bun-like all-in-one toolkit for Node.js
(news.ycombinator.com)
15.
Microsoft links Mastra AI supply chain attack to North Korean hackers
(bleepingcomputer.com)
16.
AUR Packages Compromised with Infostealer and Rootkit
(news.ycombinator.com)
17.
GitHub announces npm security changes to tackle supply-chain attacks
(bleepingcomputer.com)
18.
New IronWorm malware hits 36 packages in npm supply-chain attack
(bleepingcomputer.com)
19.
20.
Agentic Mfw
(news.ycombinator.com)
21.
Dozens of Red Hat packages backdoored through its official NPM channel
(arstechnica.com)
22.
Dozens of Red Hat packages backdoored through its offical NPM channel
(arstechnica.com)
23.
Red Hat npm packages compromised to steal developer credentials
(bleepingcomputer.com)
24.
25.
Show HN: DepsGuard – one command to harden NPM/pnpm/yarn/bun/uv configs
(news.ycombinator.com)
26.
Malicious npm packages detected across Red Hat Cloud Services
(news.ycombinator.com)
27.
NPM packages from Red Hat have been compromised
(news.ycombinator.com)
28.
NPM packages from RedHat have been compromised
(news.ycombinator.com)
29.
Npm-scan: Modern supply chain security for the npm ecosystem
(news.ycombinator.com)
30.
Claude Code – Everything You Can Configure That the Docs Don't Tell You
(news.ycombinator.com)