npm

Tag

Cards List
#npm

@DeRonin_: USE THIS GUIDE TO PROTECT YOUR COMPUTER FROM NPM HACKS THAT STEAL EVERYTHING IN ONE INSTALL TanStack, a code library us…

X AI KOLs Following · 11h ago

The article details a supply-chain attack on the TanStack library via NPM, offering a comprehensive guide to protect development environments by locking dependency ages, pinning versions, and auditing CI/CD pipelines and IDE extensions.

0 favorites 0 likes
#npm

Postmortem: TanStack npm supply-chain compromise

Lobsters Hottest · yesterday Cached

Detailed postmortem of a supply-chain attack on TanStack's npm packages involving cache poisoning, OIDC token extraction, and credential harvesting malware. All affected versions deprecated; users advised to rotate credentials.

0 favorites 0 likes
#npm

Show HN: Safe-install – safer NPM installs with trusted build dependencies

Hacker News Top · yesterday

A new npm package called safe-install is introduced to enhance supply chain security by allowing developers to disable install scripts by default and block exotic sub-dependencies, addressing ongoing vulnerabilities.

0 favorites 0 likes
#npm

@RhysSullivan: just enabled a minimum age on npm package installs for my machine, should've done this sooner but if you haven't either…

X AI KOLs Following · 2d ago

A developer shares a tip to configure a minimum release age for package installs to mitigate supply-chain attacks.

0 favorites 0 likes
#npm

@tan_stack: SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions tota…

X AI KOLs Following · 2d ago Cached

A high-severity supply-chain compromise affected 42 TanStack npm packages, exfiltrating cloud credentials and SSH keys. Users are advised to rotate credentials and reinstall from clean lockfiles if they installed packages during the attack window.

0 favorites 0 likes
#npm

TanStack NPM Packages Compromised

Hacker News Top · 2d ago Cached

Reports indicate a security compromise affecting TanStack NPM packages, impacting developers using the TanStack Router and Start frameworks.

0 favorites 0 likes
#npm

Incident Report: CVE-2024-YIKES

Hacker News Top · 3d ago Cached

A satirical incident report describes a catastrophic, multi-stage supply chain attack originating from a compromised JavaScript dependency and spreading through Rust and Python ecosystems before being accidentally resolved by a mining worm.

0 favorites 0 likes
#npm

ActionFence: A drop-in middleware for MCP servers to enforce spend caps and policy limits

Reddit r/AI_Agents · 4d ago

ActionFence is an open-source middleware tool for enforcing security policies, such as spend caps and identity tiers, on MCP servers and Express APIs to protect against agent misuse.

0 favorites 0 likes
#npm

Features everyone should steal from npmx

Lobsters Hottest · 2026-04-21 Cached

npmx is an MIT-licensed alternative web frontend for the npm registry that adds security and usability features—like transitive install sizes, install-script disclosure, and outdated/vulnerable-dependency trees—spurring npmjs.com to finally ship dark mode.

0 favorites 0 likes
#npm

openai/openai-node v6.31.0

GitHub Releases Watchlist · 2026-03-16 Cached

OpenAI Node.js SDK v6.31.0 release - TypeScript/JavaScript library for accessing OpenAI's REST API with support for Chat Completions and Responses APIs, featuring workload identity authentication for cloud environments.

0 favorites 0 likes
← Back to home

Submit Feedback