npm

Tag

Cards List
#npm

Why does mathmain need an encrypted loader?

Hacker News Top ↗ · 2026-09-21 Cached

This article reveals that the npm package mathmain contains a hidden remote access implant with an encrypted loader, which decrypts and executes malicious code when a specific equation is solved using the library.

0 favorites 0 likes
#npm

@colifran_: openwiki cursor we recently made openwiki more accessible than ever with coding agent integrations. our newest integrat…

X AI KOLs Timeline ↗ · 2026-09-02 Cached

OpenWiki announces a new integration with Cursor, enhancing its accessibility for coding agents. The integration allows users to install and set up with just two npm commands.

0 favorites 0 likes
#npm

@rauchg: MCP is growing explosively. And it's not just Vercel MCP… Look at 𝚖𝚌𝚙-𝚑𝚊𝚗𝚍𝚕𝚎𝚛 npm downloads, which you can us…

X AI KOLs Timeline ↗ · 2026-08-28 Cached

The Model Context Protocol (MCP) is experiencing explosive growth, with Vercel reporting a 564% increase in tool calls over three months and rising npm downloads for mcp-handler.

0 favorites 0 likes
#npm

@github: Dependabot now waits three days before non-security version update pull requests, giving scanners time to catch a poiso…

X AI KOLs Timeline ↗ · 2026-08-23 Cached

GitHub's Dependabot now implements a three-day cooldown for non-security version updates to give security scanners time to detect poisoned releases, helping mitigate supply chain attacks.

0 favorites 0 likes
#npm

@IndieDevHailey: Discovered an interesting collection of animations and instantly got hooked. He's recently working on an open-source project called Comimi, a comic reader library for the web (JS/TS). It's not just a simple page-turning toy, but something that truly considers the actual reading experience. The video demonstrates it clearly: Supports standard/widescreen/full-screen switching…

X AI KOLs Timeline ↗ · 2026-08-22 Cached

Introducing the open-source project Comimi, a comic reader library designed for the web, supporting multiple reading modes, customizable features, and a lightweight implementation, focused on enhancing the actual reading experience.

0 favorites 0 likes
#npm

@ericzakariasson: i turned this into an npm package you drop a widget in your app and when someone files feedback, a cloud agent opens a …

X AI KOLs Timeline ↗ · 2026-08-15 Cached

An npm package that automates feedback handling in apps by opening pull requests through a cloud agent.

0 favorites 0 likes
#npm

@MoureDev: This library converts Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, and PDF documents to Markdown! Essential g…

X AI KOLs Timeline ↗ · 2026-08-05 Cached

Una librería en Rust que convierte documentos Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV y PDF a Markdown, disponible vía npm, Python y CLI, destacando su utilidad para LLMs.

0 favorites 0 likes
#npm

Keyv and friends compromised in active Shai-Hulud supply chain attack

Hacker News Top ↗ · 2026-08-04 Cached

Attackers compromised the GitHub account of the maintainer behind keyv and related npm caching libraries, injecting a credential-stealing worm across multiple packages with over 2 billion combined monthly installs.

0 favorites 0 likes
#npm

npm i -g hotcell

Product Hunt ↗ · 2026-08-03

Hotcell provides local sandboxes for AI agents on Mac, Linux, and bare metal, installable via npm.

0 favorites 0 likes
#npm

OpenClaw is maturing 🦞 Extended-STABLE releases are HERE

Reddit r/openclaw ↗ · 2026-07-30

OpenClaw announces extended-stable releases with monthly backported fixes and a public maturity scorecard, moving closer to official LTS support.

0 favorites 0 likes
#npm

Disrupting supply chain attacks on NPM and GitHub Actions

Hacker News Top ↗ · 2026-07-29 Cached

GitHub announces new security measures for npm and GitHub Actions to disrupt common supply chain attack techniques, including preventive account protection for high-impact accounts and safer default checkout settings.

0 favorites 0 likes
#npm

@OpenAI: Install the open-source Codex Security CLI,: npm install @OpenAI/codex-security Or start with: npx @OpenAI/codex-securi…

X AI KOLs ↗ · 2026-07-29

OpenAI released the open-source Codex Security CLI, available via npm, to help developers with security tasks.

0 favorites 0 likes
#npm

@Docker: The malware didn't bring its own credential scanner. It borrowed yours. In this AI Coding Agent Horror Stories issue: @…

X AI KOLs Timeline ↗ · 2026-07-28 Cached

A malicious npm package (s1ngularity) exploited post-install hooks to repurpose installed AI coding agents as credential scanners, stealing secrets from developers. Docker's blog discusses how Docker Sandboxes can mitigate such attacks by isolating credentials from agent reach.

0 favorites 0 likes
#npm

Dependency Cultures - Richard Feldman (Software Should Work Conf 2026)

Lobsters Hottest ↗ · 2026-07-28 Cached

Richard Feldman compares dependency graphs of different programming language websites and games, pointing out that most dependency choices are cultural norms rather than technical necessities.

0 favorites 0 likes
#npm

Pkgxray – inspect what gets installed, not what executes

Hacker News Top ↗ · 2026-07-22 Cached

pkgxray is a zero-dependency static analysis tool that inspects npm packages and MCP servers before installation, providing SAFE/REVIEW/BLOCK verdicts to prevent supply-chain attacks.

0 favorites 0 likes
#npm

My coding agent installed loadash. how do you hard-block fake packages before postinstall runs

Reddit r/AI_Agents ↗ · 2026-07-16

Discusses the problem of AI coding agents installing typo-squatted npm packages (like loadash) and asks for methods to block such fakes before postinstall scripts run.

0 favorites 0 likes
#npm

@trq212: I've been playing a lot of Pokemon Champions recently and started using Claude Code to help me. It writes code using Sm…

X AI KOLs Following ↗ · 2026-07-14 Cached

The user describes using Claude Code to interact with Smogon's npm library for Pokemon Champions, pulling live usage stats and generating reports for matchups and team building.

0 favorites 0 likes
#npm

Ambient Website Background Clouds

Hacker News Top ↗ · 2026-07-10 Cached

background-clouds is a lightweight, dependency-free JavaScript library that renders an animated low-poly cloud bank behind a website using a single canvas, with support for reduced motion and SPA lifecycle methods.

0 favorites 0 likes
#npm

@kentcdodds: This is now built into Kody to make setting up new integrations a lot more straightforward for your agents https://gith…

X AI KOLs Timeline ↗ · 2026-07-04 Cached

Kody is an experimental personal assistant platform built on Cloudflare Workers and MCP; a recent update simplifies integration setup for agents.

0 favorites 0 likes
#npm

@rauchg: "Can @v0 use my design system?" you've asked. Now the answer is: @v0 can use the exact same components your product use…

X AI KOLs Following ↗ · 2026-06-25 Cached

v0 can now use the exact same components from your design system, supporting imports from GitHub, npm, Storybook, Figma, and more. Tested with Microsoft Fluent, Shopify Polaris, IBM Carbon, Palantir Blueprint, and Vercel Geist.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback