Tag
This article reveals that the npm package mathmain contains a hidden remote access implant with an encrypted loader, which decrypts and executes malicious code when a specific equation is solved using the library.
OpenWiki announces a new integration with Cursor, enhancing its accessibility for coding agents. The integration allows users to install and set up with just two npm commands.
The Model Context Protocol (MCP) is experiencing explosive growth, with Vercel reporting a 564% increase in tool calls over three months and rising npm downloads for mcp-handler.
GitHub's Dependabot now implements a three-day cooldown for non-security version updates to give security scanners time to detect poisoned releases, helping mitigate supply chain attacks.
Introducing the open-source project Comimi, a comic reader library designed for the web, supporting multiple reading modes, customizable features, and a lightweight implementation, focused on enhancing the actual reading experience.
An npm package that automates feedback handling in apps by opening pull requests through a cloud agent.
Una librería en Rust que convierte documentos Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV y PDF a Markdown, disponible vía npm, Python y CLI, destacando su utilidad para LLMs.
Attackers compromised the GitHub account of the maintainer behind keyv and related npm caching libraries, injecting a credential-stealing worm across multiple packages with over 2 billion combined monthly installs.
Hotcell provides local sandboxes for AI agents on Mac, Linux, and bare metal, installable via npm.
OpenClaw announces extended-stable releases with monthly backported fixes and a public maturity scorecard, moving closer to official LTS support.
GitHub announces new security measures for npm and GitHub Actions to disrupt common supply chain attack techniques, including preventive account protection for high-impact accounts and safer default checkout settings.
OpenAI released the open-source Codex Security CLI, available via npm, to help developers with security tasks.
A malicious npm package (s1ngularity) exploited post-install hooks to repurpose installed AI coding agents as credential scanners, stealing secrets from developers. Docker's blog discusses how Docker Sandboxes can mitigate such attacks by isolating credentials from agent reach.
Richard Feldman compares dependency graphs of different programming language websites and games, pointing out that most dependency choices are cultural norms rather than technical necessities.
pkgxray is a zero-dependency static analysis tool that inspects npm packages and MCP servers before installation, providing SAFE/REVIEW/BLOCK verdicts to prevent supply-chain attacks.
Discusses the problem of AI coding agents installing typo-squatted npm packages (like loadash) and asks for methods to block such fakes before postinstall scripts run.
The user describes using Claude Code to interact with Smogon's npm library for Pokemon Champions, pulling live usage stats and generating reports for matchups and team building.
background-clouds is a lightweight, dependency-free JavaScript library that renders an animated low-poly cloud bank behind a website using a single canvas, with support for reduced motion and SPA lifecycle methods.
Kody is an experimental personal assistant platform built on Cloudflare Workers and MCP; a recent update simplifies integration setup for agents.
v0 can now use the exact same components from your design system, supporting imports from GitHub, npm, Storybook, Figma, and more. Tested with Microsoft Fluent, Shopify Polaris, IBM Carbon, Palantir Blueprint, and Vercel Geist.