TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages ...
TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and ...
NPM and PRX have teamed up to develop a powerful and streamlined collaborative solution. Stations using or considering PRX's Dovetail podcast publishing and monetization platform — available to ...
GitHub’s internal repositories — now staged publishing in npm 11.15.0 requires a human 2FA approval before any package goes ...
GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ...
The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, ...
Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings ...
The OWASP-backed tool scans JavaScript and TypeScript lockfiles locally, aiming to help developers catch and remediate dependency risks before CI failures.
A Shai-Hulud copycat has turned up in yet another npm package just five days after TeamPCP open sourced the worm and ...
Perplexity launches Bumblebee: How its new read-only dev scanner differs from Chainguard ...