npm

Tag

Cards List
#npm

Staged publishing and new install-time controls for npm

Hacker News Top · 2026-05-22 Cached

npm introduces staged publishing, requiring human approval via 2FA for package releases, and new `--allow-*` flags (file, remote, directory) to control install sources, improving supply-chain security in npm CLI 11.15.0.

0 favorites 0 likes
#npm

Staged publishing for npm packages

Lobsters Hottest · 2026-05-20 Cached

npm introduces staged publishing, allowing package updates to be reviewed and approved with 2FA before going live on the registry, enhancing security for package maintainers.

0 favorites 0 likes
#npm

Grafana Labs GitHub repos breached via TanStack npm supply chain attack

Lobsters Hottest · 2026-05-20 Cached

Grafana Labs disclosed that a cybercrime group gained unauthorized access to its GitHub repositories via a TanStack npm supply chain attack, downloading codebase and internal data, but no customer production systems were compromised.

0 favorites 0 likes
#npm

@seclink: Nationwide emergency response today — an open-source frontend library suffered a supply chain attack; any project using it may be infected with a worm. Urgent checks and upgrades needed.

X AI KOLs Following · 2026-05-19 Cached

Nationwide emergency response today because AntV, an open-source frontend library by Ant Group, was hit by a supply chain attack and implanted with a worm. Users need to urgently check and upgrade.

0 favorites 0 likes
#npm

Show HN: Id-agent – Token efficient UUID alternative for AI agents

Hacker News Top · 2026-05-19 Cached

id-agent is an open-source npm library that generates human-readable, token-efficient word-based IDs as a UUID alternative for AI agents, reducing token costs by ~40% while maintaining collision resistance.

0 favorites 0 likes
#npm

Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

Hacker News Top · 2026-05-19 Cached

The npm account 'atool' was compromised, leading to the publication of 637 malicious versions across 317 packages. The payload harvests credentials, establishes persistence via AI coding tools and system services, and exfiltrates data through GitHub.

0 favorites 0 likes
#npm

@libapi_: Hermes Web UI started from 0 last month. As of today: GitHub 5,000 stars, npm 139,333 downloads in 30 days, official site 216.65K requests in 30 days. Honestly, I'm really happy, super happy seeing it slowly spread in the domestic community…

X AI KOLs Timeline · 2026-05-16 Cached

The Hermes Web UI project started from scratch last month and within one month achieved 5,000 GitHub stars, 139k npm downloads, and 216k official site requests. The author expressed great joy and gratitude for community support.

0 favorites 0 likes
#npm

@GitTrend0x: 46 AI agents 杀手级开源神器 https://github.com/rohitg00/skillkit… 这就是 SkillKit,1k star 爆款 AI coding agent 技能包管理器!

X AI KOLs Timeline · 2026-05-16 Cached

SkillKit is a package manager for AI coding agent skills, supporting 46 agents and 400K+ skills from 31 sources, allowing one skill to be used across multiple agents.

0 favorites 0 likes
#npm

'No way to prevent this,' says only package manager where this regularly happens

Hacker News Top · 2026-05-16 Cached

Satirical article highlighting the recurring supply chain attacks in the npm registry, contrasting with more secure ecosystems like Go and Rust, and mocking the JavaScript community's acceptance of such vulnerabilities.

0 favorites 0 likes
#npm

@altryne: PSA: If you are un-aware of the latest supply-chain attacks, or aware but complacent and didn't do anything, especially…

X AI KOLs Following · 2026-05-15 Cached

A PSA about a series of supply-chain attacks targeting AI developer tools (Hermes, OpenClaw) via npm and PyPI, specifically the 'Mini-Shai Hulud' worm that self-replicates and steals credentials, API keys, and browser sessions. The post advises sandboxed execution and restricting package age to mitigate risks.

0 favorites 0 likes
#npm

@jahooma: We just launched our 100% free coding agent everywhere. Every person in the world has access to 5 free hours of DeepSee…

X AI KOLs Timeline · 2026-05-15 Cached

Launched free coding agent 'freebuff' with 5 free hours of DeepSeek V4 Flash daily for everyone.

0 favorites 0 likes
#npm

@DeRonin_: USE THIS GUIDE TO PROTECT YOUR COMPUTER FROM NPM HACKS THAT STEAL EVERYTHING IN ONE INSTALL TanStack, a code library us…

X AI KOLs Following · 2026-05-13

The article details a supply-chain attack on the TanStack library via NPM, offering a comprehensive guide to protect development environments by locking dependency ages, pinning versions, and auditing CI/CD pipelines and IDE extensions.

0 favorites 0 likes
#npm

Our response to the TanStack npm supply chain attack

OpenAI Blog · 2026-05-13 Cached

OpenAI responds to the TanStack npm supply chain attack, stating that no user data or production systems were compromised, but two employee devices were impacted and limited credentials exfiltrated from internal code repositories.

0 favorites 0 likes
#npm

Postmortem: TanStack npm supply-chain compromise

Lobsters Hottest · 2026-05-12 Cached

Detailed postmortem of a supply-chain attack on TanStack's npm packages involving cache poisoning, OIDC token extraction, and credential harvesting malware. All affected versions deprecated; users advised to rotate credentials.

0 favorites 0 likes
#npm

Show HN: Safe-install – safer NPM installs with trusted build dependencies

Hacker News Top · 2026-05-12

A new npm package called safe-install is introduced to enhance supply chain security by allowing developers to disable install scripts by default and block exotic sub-dependencies, addressing ongoing vulnerabilities.

0 favorites 0 likes
#npm

@RhysSullivan: just enabled a minimum age on npm package installs for my machine, should've done this sooner but if you haven't either…

X AI KOLs Following · 2026-05-11

A developer shares a tip to configure a minimum release age for package installs to mitigate supply-chain attacks.

0 favorites 0 likes
#npm

@tan_stack: SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions tota…

X AI KOLs Following · 2026-05-11 Cached

A high-severity supply-chain compromise affected 42 TanStack npm packages, exfiltrating cloud credentials and SSH keys. Users are advised to rotate credentials and reinstall from clean lockfiles if they installed packages during the attack window.

0 favorites 0 likes
#npm

TanStack NPM Packages Compromised

Hacker News Top · 2026-05-11 Cached

Reports indicate a security compromise affecting TanStack NPM packages, impacting developers using the TanStack Router and Start frameworks.

0 favorites 0 likes
#npm

Incident Report: CVE-2024-YIKES

Hacker News Top · 2026-05-10 Cached

A satirical incident report describes a catastrophic, multi-stage supply chain attack originating from a compromised JavaScript dependency and spreading through Rust and Python ecosystems before being accidentally resolved by a mining worm.

0 favorites 0 likes
#npm

ActionFence: A drop-in middleware for MCP servers to enforce spend caps and policy limits

Reddit r/AI_Agents · 2026-05-09

ActionFence is an open-source middleware tool for enforcing security policies, such as spend caps and identity tiers, on MCP servers and Express APIs to protect against agent misuse.

0 favorites 0 likes
← Previous
Next →
← Back to home

Submit Feedback