@anon
sign up
@anon
sign up
pull down to refresh
Bogus npm Packages Used to Trick Software Developers into Installing Malware
thehackernews.com/2024/04/bogus-npm-packages-used-to-trick.html?m=1
42 sats
\
1 comment
\
@ch0k1
28 Apr 2024
security
related
Malicious npm Packages Found Using Image Files to Hide Backdoor Code
thehackernews.com/2024/07/malicious-npm-packages-found-using.html?m=1
23 sats
\
0 comments
\
@ch0k1
19 Jul 2024
news
North Korean Hackers Targeting Developers with Malicious npm Packages
thehackernews.com/2024/02/north-korean-hackers-targeting.html
23 sats
\
0 comments
\
@doofus
28 Feb 2024
security
Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor
thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html
24 sats
\
0 comments
\
@ch0k1
11 May
news
Self-Replicating Worm Hits 180+ Software Packages
krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/
50 sats
\
0 comments
\
@ch0k1
16 Sep
news
NPM hack was mentioned multiple times on SN before yesterday
130 sats
\
4 comments
\
@nolem
9 Sep
bitdevs
Malicious Microsoft VSCode extensions target devs, crypto community
www.bleepingcomputer.com/news/security/malicious-microsoft-vscode-extensions-target-devs-crypto-community/
30 sats
\
0 comments
\
@ch0k1
18 Dec 2024
security
Over 100,000 Infected Repos Found on GitHub
1687 sats
\
6 comments
\
@0xbitcoiner
29 Feb 2024
security
NPM security: preventing supply chain attacks | Snyk (2022)
snyk.io/blog/npm-security-preventing-supply-chain-attacks/
417 sats
\
20 comments
\
@ek
9 Sep
security
Nearly 20% of Docker Hub Repositories Spread Malware & Phishing Scams
jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/
154 sats
\
1 comment
\
@nym
30 Apr 2024
security
'GoIssue' Cybercrime Tool Targets GitHub Developers En Masse
www.darkreading.com/cloud-security/goissue-cybercrime-tool-github-developers-en-masse
18 sats
\
0 comments
\
@ch0k1
14 Nov 2024
security
Commercial Spyware Vendors Are Behind Most Zero-Day Exploits
securityaffairs.com/158750/hacking/commercial-spyware-vendors-zero-day.html
413 sats
\
0 comments
\
@0xbitcoiner
6 Feb 2024
security
100+ backdoored malware repos traced to single GitHub user
www.theregister.com/2025/06/05/backdoored_malware_repos
51 sats
\
1 comment
\
@Coinsreporter
5 Jun
security
Hugging Face, the GitHub of AI, Hosted Code That Backdoored User Devices
arstechnica.com/security/2024/03/hugging-face-the-github-of-ai-hosted-code-that-backdoored-user-devices/
71 sats
\
1 comment
\
@0xbitcoiner
3 Mar 2024
security
Backdoor Slipped Into Popular Code Library, Drains ~$155k From SOL Wallets
arstechnica.com/information-technology/2024/12/backdoor-slips-into-popular-code-library-drains-155k-from-digital-wallets/
81 sats
\
0 comments
\
@0xbitcoiner
5 Dec 2024
security
how to compromise security critical open source projects (NSA keynote, 2014)
archive.md/WwaAW
142 sats
\
1 comment
\
@standardcrypto
22 Sep
bitcoin
Self Propagating NPM Malware Compromises over 40 Packages
www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised
100 sats
\
0 comments
\
@hn
16 Sep
tech
We Just Found Malicious Code in the Popular NPM Package
jdstaerk.substack.com/p/we-just-found-malicious-code-in-the
1397 sats
\
18 comments
\
@kristapsk
8 Sep
security
Snyk security researcher deploys malicious NPM packages targeting Cursor.com
sourcecodered.com/snyk-malicious-npm-package/
34 sats
\
0 comments
\
@hn
14 Jan
tech
NPM debug and chalk packages compromised
www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
233 sats
\
0 comments
\
@hn
8 Sep
tech
Malicious VSCode extensions with millions of installs discovered
www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/
370 sats
\
0 comments
\
@Rsync25
9 Jun 2024
security
Npm Run Hack:Me - A Supply Chain Attack Journey
rxj.dev/posts/npm-run-hack-supply-chain-attack-journey/
161 sats
\
1 comment
\
@k00b
12 Mar
devs
more