Heykuki News

TopNewBestAskShowJobs
TopNewBestAskShowJobs
1.
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised (socket.dev)
1233 points
jamesberthoty
9 months ago
1019 comments
2.
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library (semgrep.dev)
465 points
j12y
a month ago
177 comments
3.
Show HN: Socket – Secure your JavaScript supply chain (socket.dev)
133 points
feross
4 years ago
42 comments
4.
Show HN: Resource Index – FOSS Git Repository and NPM Package Index (res-index.hkit.cc)
14 points
aabbcc1241
2 years ago
4 comments
5.
Show HN: Socket web extension – free NPM supply chain protection (chrome.google.com)
10 points
101arrowz
3 years ago
6 comments
6.
Show HN: Aidevshield NPM audit for AI coding tool workflows (github.com/aidevshield)
1 point
GrimLabs
3 months ago
discuss
7.
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign (socket.dev)
872 points
tosh
a month ago
431 comments
8.
Trivy under attack again: Widespread GitHub Actions tag compromise secrets (socket.dev)
250 points
jicea
2 months ago
83 comments
9.
NPM to implement staged publishing after turbulent shift off classic tokens (socket.dev)
205 points
feross
5 months ago
125 comments
10.
The Everything NPM Package (socket.dev)
192 points
defied
2 years ago
151 comments
11.
The push to ban ransom payments is gaining momentum (socket.dev)
127 points
feross
2 years ago
166 comments
12.
Social engineering campaign targeting tech employees spreads through NPM malware (socket.dev)
114 points
feross
3 years ago
87 comments
13.
Active NPM supply chain attack: Tinycolor and 40 Packages Compromised (socket.dev)
85 points
feross
9 months ago
36 comments
14.
German Court Fines Security Researcher for Reporting Company's Vulnerabilities (socket.dev)
77 points
ankitdce
2 years ago
34 comments
15.
OpenJS: "XZ Utils Cyberattack Likely Not an Isolated Incident" (socket.dev)
65 points
feross
2 years ago
25 comments
16.
What's Going on Inside Your Node_modules Folder? (socket.dev)
64 points
swyx
4 years ago
33 comments
17.
Chinese devs are storing 1000s of eBooks on GitHub and NPM (socket.dev)
62 points
feross
4 years ago
12 comments
18.
Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum (socket.dev)
53 points
feross
2 years ago
4 comments
19.
Prettier NPM Packages Compromised in Supply Chain Attack (socket.dev)
45 points
feross
a year ago
7 comments
20.
Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack (socket.dev)
42 points
feross
2 years ago
9 comments
21.
Curl Project and Go Security Teams Reject CVSS as Broken (socket.dev)
40 points
feross
a year ago
10 comments
22.
AI Hallucinations Are Fueling a New Class of Supply Chain Attacks (socket.dev)
31 points
sksxihve
a year ago
6 comments
23.
Gem.Coop – Community-Run Alternative to Rubygems.org, Led by Former Maintainers (socket.dev)
30 points
ciconia
8 months ago
3 comments
24.
Libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable (socket.dev)
27 points
feross
a year ago
8 comments
25.
DuckDB NPM Account Compromised in Continuing Supply Chain Attack (socket.dev)
27 points
feross
9 months ago
1 comment
26.
Automated Spam Campaign Floods GitHub/NPM with 1000s of Garbage Packages (socket.dev)
25 points
feross
2 years ago
4 comments
27.
New Rust RFC Proposes Adding Support for Trusted Publishing to Crates.io (socket.dev)
24 points
feross
2 years ago
13 comments
28.
New Proposed CISA Mandate Would Require Critical Infrastructure to Report Ransom (socket.dev)
19 points
feross
2 years ago
1 comment
29.
Go Supply Chain Attack: Malicious Package Exploits Go Module Proxy Caching For (socket.dev)
17 points
feross
a year ago
3 comments
30.
Go Supply Chain Attack: Malicious Package Exploits Go Module (socket.dev)
17 points
bamazizi
a year ago
discuss
More