mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,4 Tsd.
aktive Profile

#npm

61 Beiträge53 Beteiligte0 Beiträge heute
Wervice 🦀<p>Seeing the recent events going on with <a href="https://fosstodon.org/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> I removed node from my computer for now.</p><p>It think, who ever is doing those attacks really doesn't care a bit about the maintainers behind the packages.</p><p>What do you think about this?</p><p><a href="https://fosstodon.org/tags/javascript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>javascript</span></a></p>
MrB33n<p>The Hidden Fragility: Supply Chain Security in Open Source (RubyGems, NPM, PyPI)</p><p><a href="https://comuniq.xyz/post?t=340" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">comuniq.xyz/post?t=340</span><span class="invisible"></span></a> <a href="https://mastodon.social/tags/tech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tech</span></a> <a href="https://mastodon.social/tags/technology" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>technology</span></a> <a href="https://mastodon.social/tags/hacker" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hacker</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a></p>
Johannes Schnatterer<p>TLDR recent <a href="https://floss.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> supply chain attacks</p><p>🗓️ 26 Aug: <a href="https://floss.social/tags/nx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nx</span></a> packages compromised stealing SSH keys, npm tokens, and .gitconfig files and weaponized AI CLI tools 😱 upload to repo named <a href="https://floss.social/tags/S1ngularity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>S1ngularity</span></a><br>HackerNews: <a href="https://news.ycombinator.com/item?id=45034496" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.ycombinator.com/item?id=4</span><span class="invisible">5034496</span></a><br>GHSA-cxm3-wv7p-598c: <a href="https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/nrwl/nx/security/ad</span><span class="invisible">visories/GHSA-cxm3-wv7p-598c</span></a></p><p>🗓️ 8 Sep: <a href="https://floss.social/tags/chalk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>chalk</span></a>, <a href="https://floss.social/tags/debugjs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>debugjs</span></a> and other packages by maintainer <a href="https://floss.social/tags/qix" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>qix</span></a> (junon) compromised. They handled this very transparently 👍️<br>See <br>HackerNews: <a href="https://news.ycombinator.com/item?id=45169794" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.ycombinator.com/item?id=4</span><span class="invisible">5169794</span></a><br>CVE-2025-59144: <a href="https://github.com/advisories/GHSA-4x49-vf9v-38px" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/advisories/GHSA-4x4</span><span class="invisible">9-vf9v-38px</span></a></p>
Jacket<p>After the 3, yes, THREE! Dependency attacks using <a href="https://tech.lgbt/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a>, </p><p>1: please lock your version and run tools to figure out if you have vulnerabilities in you dependencies.</p><p>2: Maybe integrating the most used functionality in the language is a good thing instead of relying on a million deps like in <a href="https://tech.lgbt/tags/javascipt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>javascipt</span></a> or <a href="https://tech.lgbt/tags/python" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>python</span></a>.</p>
Scott Wilson<p>More about the npm “worm”, from Palo Alto’s Unit 42 threat intelligence team: </p><p>“Assume that any secret present on a developer's machine may have been compromised.”</p><p>That’s a big deal. </p><p><a href="https://infosec.exchange/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://infosec.exchange/tags/nodejs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nodejs</span></a> <a href="https://infosec.exchange/tags/SBOM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SBOM</span></a> <a href="https://infosec.exchange/tags/software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>software</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p><p><a href="https://unit42.paloaltonetworks.com/npm-supply-chain-attack/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">unit42.paloaltonetworks.com/np</span><span class="invisible">m-supply-chain-attack/</span></a></p>
Scott Wilson<p>Lots of people are asking why the npm and Node.js thing are so dangerous… </p><p>There are “over 3.1 million packages are available in the main npm registry”, and there’s no mechanism to review or approve the packages. 🤔</p><p><a href="https://infosec.exchange/tags/javascript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>javascript</span></a> <a href="https://infosec.exchange/tags/nodejs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nodejs</span></a> <a href="https://infosec.exchange/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>software</span></a> <a href="https://infosec.exchange/tags/SBOM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SBOM</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>Aikido Safe Chain</p><p>The Aikido Safe Chain prevents developers from installing malware on their workstations through npm, npx, yarn, pnpm and pnpx. It's free to use and does not require any token.</p><p>✅ <a href="https://www.npmjs.com/package/@aikidosec/safe-chain" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">npmjs.com/package/@aikidosec/s</span><span class="invisible">afe-chain</span></a></p><p><a href="https://chaos.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://chaos.social/tags/javasript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>javasript</span></a> <a href="https://chaos.social/tags/savechain" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>savechain</span></a> <a href="https://chaos.social/tags/aikido" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aikido</span></a> <a href="https://chaos.social/tags/js" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>js</span></a> <a href="https://chaos.social/tags/ts" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ts</span></a> <a href="https://chaos.social/tags/webdev" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>webdev</span></a> <a href="https://chaos.social/tags/typescript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>typescript</span></a> <a href="https://chaos.social/tags/npmjs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npmjs</span></a> <a href="https://chaos.social/tags/web" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>web</span></a> <a href="https://chaos.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsecurity</span></a> <a href="https://chaos.social/tags/npmhell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npmhell</span></a> <a href="https://chaos.social/tags/hacking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hacking</span></a> <a href="https://chaos.social/tags/hackers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hackers</span></a> <a href="https://chaos.social/tags/npx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npx</span></a> <a href="https://chaos.social/tags/yarn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yarn</span></a> <a href="https://chaos.social/tags/pnpm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pnpm</span></a> <a href="https://chaos.social/tags/pnpx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pnpx</span></a> <a href="https://chaos.social/tags/bun" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bun</span></a></p>
Sascha Presnac 🙄🤦‍♂️<p>Got some proposals for renaming the <a href="https://mastodon.online/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> commands:</p><p>`npm pray install xyz`<br>`npm dare update`<br>`npm maybe install xyz`</p>
.:\dGh/:.<p>You have to be shitting me. God I fucking hate npm.</p><p>I literally spent an hour trying to diagnose why the builder was "freezeing" for several minutes, and it's because it downloads thousands of packages for a project with... 20 dependencies.</p><p>Fuck NPM. Fuck JavaScript.</p><p><a href="https://mastodon.social/tags/Programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Programming</span></a> <a href="https://mastodon.social/tags/JavaScript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JavaScript</span></a> <a href="https://mastodon.social/tags/Node" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Node</span></a> <a href="https://mastodon.social/tags/NodeJS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NodeJS</span></a> <a href="https://mastodon.social/tags/JS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JS</span></a> <a href="https://mastodon.social/tags/ECMAScript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ECMAScript</span></a> <a href="https://mastodon.social/tags/NPM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NPM</span></a> <a href="https://mastodon.social/tags/PackageManagers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PackageManagers</span></a> <a href="https://mastodon.social/tags/SoftwareDevelopment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareDevelopment</span></a> <a href="https://mastodon.social/tags/WebDevelopment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebDevelopment</span></a> <a href="https://mastodon.social/tags/WebDev" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebDev</span></a></p>
Inautilo<p><a href="https://mastodon.social/tags/Development" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Development</span></a> <a href="https://mastodon.social/tags/Analyses" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Analyses</span></a><br>Oh no, not again... · “NPM has become the easiest way to ship malware.” <a href="https://ilo.im/166ych" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">ilo.im/166ych</span><span class="invisible"></span></a></p><p>_____<br><a href="https://mastodon.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://mastodon.social/tags/GitHub" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GitHub</span></a> <a href="https://mastodon.social/tags/Npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Npm</span></a> <a href="https://mastodon.social/tags/NodeJS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NodeJS</span></a> <a href="https://mastodon.social/tags/JavaScript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JavaScript</span></a> <a href="https://mastodon.social/tags/Malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Malware</span></a> <a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/WebDev" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebDev</span></a> <a href="https://mastodon.social/tags/Frontend" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Frontend</span></a> <a href="https://mastodon.social/tags/Backend" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Backend</span></a></p>
GripNews<p>🌗 npm 供應鏈攻擊事件深入解析:<span class="h-card" translate="no"><a href="https://mastodon.social/@ctrl" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ctrl</span></a></span>/tinycolor 套件遭惡意推送<br>➤ 揭露 npm 供應鏈攻擊的技術細節與防範之道<br>✤ <a href="https://sigh.dev/posts/ctrl-tinycolor-post-mortem/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">sigh.dev/posts/ctrl-tinycolor-</span><span class="invisible">post-mortem/</span></a><br>本文作者 Scott Cooper 深入剖析了其維護的 <span class="h-card" translate="no"><a href="https://mastodon.social/@ctrl" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ctrl</span></a></span>/tinycolor 套件遭受npm供應鏈攻擊的事件。攻擊者利用共享儲存庫的權限漏洞,透過惡意 GitHub Actions 工作流程竊取了具有廣泛發布權限的 npm 權杖,並藉此推送了包含惡意後門的套件版本。作者強調自身帳號和儲存庫並未直接被入侵,也未使用受感染的套件。事件發生後,GitHub 和 npm 安全團隊迅速採取行動,下架了惡意版本,作者也重新發布了乾淨版本以恢復信任。文章並探討了現有發布機制的不足,並提出了未來安全發布的改進建議,例如採用 npm 的 Trusted Publishing (OIDC) 及加強 2FA 驗證。<br>+ 這篇文章解釋得很清楚,幸好作者和安全團隊反應快,不<br><a href="https://mastodon.social/tags/%E4%BE%9B%E6%87%89%E9%8F%88%E6%94%BB%E6%93%8A" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>供應鏈攻擊</span></a> <a href="https://mastodon.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://mastodon.social/tags/GitHub" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GitHub</span></a> Actions <a href="https://mastodon.social/tags/%E5%AE%89%E5%85%A8%E6%80%A7" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>安全性</span></a> <a href="https://mastodon.social/tags/TypeScript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TypeScript</span></a></p>
Evan Hahn<p>"A better future for JavaScript that won't happen" <a href="https://drewdevault.com/2025/09/17/2025-09-17-An-impossible-future-for-JS.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">drewdevault.com/2025/09/17/202</span><span class="invisible">5-09-17-An-impossible-future-for-JS.html</span></a></p><p><a href="https://bigshoulders.city/tags/JavaScript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JavaScript</span></a> <a href="https://bigshoulders.city/tags/programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>programming</span></a> <a href="https://bigshoulders.city/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://bigshoulders.city/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@technadu" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>technadu</span></a></span> After <a href="https://infosec.space/tags/CrowdStroke" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CrowdStroke</span></a> it should be clear that <a href="https://infosec.space/tags/CrowdStrike" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CrowdStrike</span></a> isn't a <em>"trustworthy brand"</em>...</p><ul><li>Granted everyone who thinks 3rd party <a href="https://infosec.space/tags/rootkits" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rootkits</span></a> like CrowdStrike in a <a href="https://infosec.space/tags/CCSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CCSS</span></a> <a href="https://infosec.space/tags/Govware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Govware</span></a> masquerading as an <a href="https://infosec.space/tags/OS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OS</span></a> (<a href="https://infosec.space/tags/windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windows</span></a>) is a valid security strategy should not be trusted even with a light switch or plastic fork.</li></ul><p>also <a href="https://infosec.space/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> sucks!</p>
Christian Noll<p>New NPM attack: Self-replicating malware infects dozens of packages - By Christopher Kunz</p><p><a href="https://www.heise.de/en/news/New-NPM-attack-Self-replicating-malware-infects-dozens-of-packages-10652404.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/en/news/New-NPM-attac</span><span class="invisible">k-Self-replicating-malware-infects-dozens-of-packages-10652404.html</span></a></p><p><a href="https://mas.to/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://mas.to/tags/programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>programming</span></a> <a href="https://mas.to/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://mas.to/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p><span class="h-card" translate="no"><a href="https://muenchen.social/@olafke" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>olafke</span></a></span> da Unmengen an Webdienste u.a. auf diesen JS-Libs aufbauen sind ebenso viele betroffen.</p><p>»Millionen von Downloads — Schadcode in über 40 NPM-Pakete eingeschleust:<br>Angreifer haben es erneut geschafft, mehrere NPM-Pakete mit einer Malware zu verseuchen. Diese sucht auf Entwicklersystemen nach Anmeldedaten.«</p><p>👉 <a href="https://www.golem.de/news/millionen-von-downloads-schadcode-in-ueber-40-npm-pakete-eingeschleust-2509-200119.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">golem.de/news/millionen-von-do</span><span class="invisible">wnloads-schadcode-in-ueber-40-npm-pakete-eingeschleust-2509-200119.html</span></a><br>:mastodon: Pakete: <a href="https://chaos.social/@kubikpixel/115215475805921206" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">chaos.social/@kubikpixel/11521</span><span class="invisible">5475805921206</span></a></p><p><a href="https://chaos.social/tags/javascript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>javascript</span></a> <a href="https://chaos.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://chaos.social/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://chaos.social/tags/download" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>download</span></a> <a href="https://chaos.social/tags/js" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>js</span></a> <a href="https://chaos.social/tags/ts" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ts</span></a> <a href="https://chaos.social/tags/typescript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>typescript</span></a> <a href="https://chaos.social/tags/anmeldung" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>anmeldung</span></a> <a href="https://chaos.social/tags/daten" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>daten</span></a> <a href="https://chaos.social/tags/web" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>web</span></a> <a href="https://chaos.social/tags/internet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>internet</span></a></p>
1.44 MB<p>It seems to me that <a href="https://mastodon.social/tags/Deno" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deno</span></a> has an advantage over <a href="https://mastodon.social/tags/QuickJS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>QuickJS</span></a> as far as co-existing with <a href="https://mastodon.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a>, and I like <a href="https://mastodon.social/tags/rollupjs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rollupjs</span></a>. Plus, you don't need an ecosystem, just the monolithic binary. Yes, I know what is behind Deno, <a href="https://mastodon.social/tags/rust" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rust</span></a>, <a href="https://mastodon.social/tags/v8" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>v8</span></a> and all of that. In many ways it is a compromise of mine.</p>
Mirko Swillus<p>I just got rickrolled looking for the <a href="https://chaos.social/tags/shaihulud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>shaihulud</span></a> <a href="https://chaos.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> worm: </p><p><a href="https://github.com/janit/Shai-Hulud/blob/main/data.json" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/janit/Shai-Hulud/bl</span><span class="invisible">ob/main/data.json</span></a></p><p>(remember, double base64).</p>
Cybso :progress:­:anti_nazi:<p>Der dritte <a href="https://osna.social/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a>-Angriff in was, drei Wochen?</p><p><a href="https://www.golem.de/news/hunderte-npm-pakete-betroffen-ein-wurm-frisst-sich-durch-das-javascript-oekosystem-2509-200162.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">golem.de/news/hunderte-npm-pak</span><span class="invisible">ete-betroffen-ein-wurm-frisst-sich-durch-das-javascript-oekosystem-2509-200162.html</span></a></p><p>Verpflichtendes Package-Signing durch Maintainer, wann?</p>
Marcel SIneM(S)US<p>Neuer <a href="https://social.tchncs.de/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a>-Großangriff: Hunderte Pakete mit selbst-vermehrender <a href="https://social.tchncs.de/tags/Malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Malware</span></a> infiziert | Security <a href="https://www.heise.de/news/Neuer-NPM-Grossangriff-Selbst-vermehrende-Malware-infiziert-Dutzende-Pakete-10651111.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/Neuer-NPM-Grossa</span><span class="invisible">ngriff-Selbst-vermehrende-Malware-infiziert-Dutzende-Pakete-10651111.html</span></a> <a href="https://social.tchncs.de/tags/NodeJS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NodeJS</span></a> <a href="https://social.tchncs.de/tags/worm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>worm</span></a> <a href="https://social.tchncs.de/tags/NodePackageManager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NodePackageManager</span></a></p>
TechNadu<p>🚨 Multiple CrowdStrike npm packages compromised in Shai-Hulud supply chain attack.</p><p>⚠️ 187 packages infected<br>⚠️ Malware steals creds via TruffleHog<br>⚠️ 477 packages flagged in total</p><p><a href="https://www.technadu.com/multiple-crowdstrike-npm-packages-targeted-in-supply-chain-attack-as-attack-surface-expands/609810/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">technadu.com/multiple-crowdstr</span><span class="invisible">ike-npm-packages-targeted-in-supply-chain-attack-as-attack-surface-expands/609810/</span></a></p><p><a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://infosec.exchange/tags/SupplyChain" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SupplyChain</span></a> <a href="https://infosec.exchange/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a></p>