WeSearch
Hub / Tags / Npm
TAG · #NPM

Npm coverage.

Every story in the WeSearch catalog tagged with #npm, chronological, with view counts. Subscribe to the per-tag RSS feed to follow this topic in your reader of choice.

12 stories tagged with #npm, in publish-time order across the WeSearch catalog. Tag pages update as new stories ingest.

⌘ RSS feed for this tag →   or   search "Npm"

RELATED TAGS
#intercom2#socket2#pnpm1#monorepo1#typescript1#webdev1#javascript1#pavel-espitia1#spectr-ai1#supply-chain-attack1#malware1#cybersecurity1
THE REGISTER

The never-ending supply chain attacks worm into SAP npm packages, other dev tools

Mini Shai-Hulud caught spreading credential-stealing malware The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Inter…

8 views ·
#supply chain attack#malware
SOCKET

Ruby Gems and Go Modules Impersonate Dev Tools to Steal Secrets and Poison CI

GitHub account BufferZoneCorp published sleeper packages that later added credential theft, GitHub Actions tampering, fake go wrappers, and SSH persis...…

4 views ·
#supply chain security#malicious packages#ci/cd security
OPENSOURCEMALWARE

Intercom-client NPM package and lightning PyPI packages compromised

TeamPCP has delivered another software supply chain attack that they are calling mini shai-hulud. This campaign borrows ts best trick from North Korean campaigns like PolinRider a…

4 views ·
R/JAVASCRIPT

3 pnpm Settings to Protect Yourself from Supply Chain Attacks

6 views ·
R/NODE

3 pnpm Settings to Protect Yourself from Supply Chain Attacks

8 views ·
BLEEPINGCOMPUTER

Official SAP NPM packages compromised to steal credentials

Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers' systems.…

5 views ·
DEV.TO (TOP)

How I Structured a TypeScript Monorepo with pnpm Workspaces

When spectr-ai started as a single package, everything lived in one directory: the CLI engine, the...…

5 views ·
#pnpm#monorepo#typescript
R/CYBERSECURITY

Official SAP npm packages compromised to steal credentials

6 views ·
R/DOCKER

docker buildx finally cached my npm install properly

6 views ·
HACKER NEWS (AI / LLM)

I built OWASP-style security skill packs for LLM apps (NPM install)

18 views ·
YCOMBINATOR

HTTPS: //Www.npmjs.com/ Is Down

5 views ·
NPMJS

NPM Website Is Down

Welcome to npm's home for real-time and historical data on system performance.…

9 views ·