www.aftonbladet.se
Spotifys topplistor fylls med AI-låtar
Senaste nytt • Snabba nyheter från Aftonbladet
#npm is an active hashtag on Bluesky. In the last 30 days, 52 people shared 160 posts with it — around 5 a day. Activity is up 24% versus the previous week, peaking on Aug 25 with 11 posts.
Tags most often used together with #npm.
www.aftonbladet.se
Spotifys topplistor fylls med AI-låtar
Senaste nytt • Snabba nyheter från Aftonbladet
oliviacirce.dreamwidth.org
calmvibez.com
The WeaselBiscuit Threat: Anatomy of a Lightweight JavaScript Stealer in npm
Analysis of the WeaselBiscuit JavaScript stealer spreading via 13 npm packages to harvest sensitive Chrome extension data and developer credentials.
furry.engineer
Soatok Dreamseeker (@[email protected])
Also, https://github.com/indutny/elliptic/issues/328 I think, at this point, if you have a dependency graph that intersects with the `elliptic` package in NPM, you should excise it and replace it wit...
pkgradar.com
Flagged first: npm [email protected]
PkgRadar flagged this 1 day before MAL-2026-16332 was published. See the dated receipt and static evidence.
www.bleepingcomputer.com
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.
cyberveille.ch
Campagne npm 'btree' : malware caché dans le prototype JS, 2 millions de téléchargements hebdomadaires
Analyse publiée par Checkmarx Zero le 17 septembre 2026, portant sur une campagne de supply chain npm active ciblant les développeurs JavaScript via un paquet malveillant nommé indexed-btree, qui imite le paquet légitime sorted-btree. Contrairement aux attaques classiques, ce paquet n'utilise aucun script preinstall/postinstall.
www.hendryadrian.com
Malicious Npm Packages Evade Install-script Defenses At Runtime
The indexed-btree npm campaign hides malicious code in normal runtime behavior to bypass new GitHub and npm supply chain defenses, while impersonating the legitimate sorted-btree library. Checkmarx found the package and nine related npm packages, which exposed victims to data theft, C2 activity through Slack, Telegram, and an Ethereum smart contract, and possible trace removal by the attackers. #indexed-btree #sorted-btree #Checkmarx #GitHub #npm #Sepolia
www.cloudsek.com
GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign
ilo.im
sidebranch — worktree visual diffing
Review PRs from inside your running app: switch branches from an in-page widget and compare worktrees side by side. Loopback-only, zero dependencies.
codereportglobal.indevs.in
npm 12 Native Modules: Silent Build Failures
npm 12 can skip native install scripts without failing npm install. Learn to detect blocked builds, approve exact packages, verify binaries, and fix CI safely.
github.blog
npm extends recovery-code security holds to all accounts - GitHub Changelog
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to…
calmvibez.com
The WeaselBiscuit Threat: Anatomy of a Lightweight JavaScript Stealer in npm
Analysis of the WeaselBiscuit JavaScript stealer spreading via 13 npm packages to harvest sensitive Chrome extension data and developer credentials.
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.