Heykuki News
Top
New
Best
Ask
Show
Jobs
Toggle theme
Login
Top
New
Best
Ask
Show
Jobs
1.
▲
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
(socket.dev)
1233 points
jamesberthoty
9 months ago
1019 comments
2.
▲
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
(semgrep.dev)
465 points
j12y
a month ago
177 comments
3.
▲
Show HN: Socket – Secure your JavaScript supply chain
(socket.dev)
133 points
feross
4 years ago
42 comments
4.
▲
Show HN: Resource Index – FOSS Git Repository and NPM Package Index
(res-index.hkit.cc)
14 points
aabbcc1241
2 years ago
4 comments
5.
▲
Show HN: Socket web extension – free NPM supply chain protection
(chrome.google.com)
10 points
101arrowz
3 years ago
6 comments
6.
▲
Show HN: Aidevshield NPM audit for AI coding tool workflows
(github.com/aidevshield)
1 point
GrimLabs
3 months ago
discuss
7.
▲
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
(socket.dev)
872 points
tosh
a month ago
431 comments
8.
▲
Trivy under attack again: Widespread GitHub Actions tag compromise secrets
(socket.dev)
250 points
jicea
2 months ago
83 comments
9.
▲
NPM to implement staged publishing after turbulent shift off classic tokens
(socket.dev)
205 points
feross
5 months ago
125 comments
10.
▲
The Everything NPM Package
(socket.dev)
192 points
defied
2 years ago
151 comments
11.
▲
The push to ban ransom payments is gaining momentum
(socket.dev)
127 points
feross
2 years ago
166 comments
12.
▲
Social engineering campaign targeting tech employees spreads through NPM malware
(socket.dev)
114 points
feross
3 years ago
87 comments
13.
▲
Active NPM supply chain attack: Tinycolor and 40 Packages Compromised
(socket.dev)
85 points
feross
9 months ago
36 comments
14.
▲
German Court Fines Security Researcher for Reporting Company's Vulnerabilities
(socket.dev)
77 points
ankitdce
2 years ago
34 comments
15.
▲
OpenJS: "XZ Utils Cyberattack Likely Not an Isolated Incident"
(socket.dev)
65 points
feross
2 years ago
25 comments
16.
▲
What's Going on Inside Your Node_modules Folder?
(socket.dev)
64 points
swyx
4 years ago
33 comments
17.
▲
Chinese devs are storing 1000s of eBooks on GitHub and NPM
(socket.dev)
62 points
feross
4 years ago
12 comments
18.
▲
Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum
(socket.dev)
53 points
feross
2 years ago
4 comments
19.
▲
Prettier NPM Packages Compromised in Supply Chain Attack
(socket.dev)
45 points
feross
a year ago
7 comments
20.
▲
Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack
(socket.dev)
42 points
feross
2 years ago
9 comments
21.
▲
Curl Project and Go Security Teams Reject CVSS as Broken
(socket.dev)
40 points
feross
a year ago
10 comments
22.
▲
AI Hallucinations Are Fueling a New Class of Supply Chain Attacks
(socket.dev)
31 points
sksxihve
a year ago
6 comments
23.
▲
Gem.Coop – Community-Run Alternative to Rubygems.org, Led by Former Maintainers
(socket.dev)
30 points
ciconia
8 months ago
3 comments
24.
▲
Libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable
(socket.dev)
27 points
feross
a year ago
8 comments
25.
▲
DuckDB NPM Account Compromised in Continuing Supply Chain Attack
(socket.dev)
27 points
feross
9 months ago
1 comment
26.
▲
Automated Spam Campaign Floods GitHub/NPM with 1000s of Garbage Packages
(socket.dev)
25 points
feross
2 years ago
4 comments
27.
▲
New Rust RFC Proposes Adding Support for Trusted Publishing to Crates.io
(socket.dev)
24 points
feross
2 years ago
13 comments
28.
▲
New Proposed CISA Mandate Would Require Critical Infrastructure to Report Ransom
(socket.dev)
19 points
feross
2 years ago
1 comment
29.
▲
Go Supply Chain Attack: Malicious Package Exploits Go Module Proxy Caching For
(socket.dev)
17 points
feross
a year ago
3 comments
30.
▲
Go Supply Chain Attack: Malicious Package Exploits Go Module
(socket.dev)
17 points
bamazizi
a year ago
discuss
More