Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Gem.Coop – Community-Run Alternative to Rubygems.org, Led by Former Maintainers

PodRocket Podcast: Inside the Recent NPM Supply Chain Attacks

Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised

Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised

Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised

Active NPM supply chain attack: Tinycolor and 40 Packages Compromised

Ongoing Supply Chain Attack Targets CrowdStrike NPM Packages

DuckDB NPM Account Compromised in Continuing Supply Chain Attack

libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable Burden

Rust Support in Socket

Prettier NPM Packages Compromised in Supply Chain Attack

Contagious Interview Campaign Escalates with 67 Malicious NPM Packages and New

Libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable

Malicious NPM Packages Target Cursor AI’s macOS Users

wget to Wipeout: Malicious Go Modules Fetch Destructive Payl...

AI Hallucinations Are Fueling a New Class of Supply Chain Attacks

Malicious PyPI Package Exploited Deezer's API, Orchestrates a Distributed Piracy Operation

Go Supply Chain Attack: Malicious Package Exploits Go Module

TC39 advances proposals for RegExp Escaping, Float16Array, Redeclarable vars

React Team Updates CRA Migration Guidance After Community Pushback

Curl Project and Go Security Teams Reject CVSS as Broken

New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs

Sonar to Acquire Tidelift, Scaling Open Source Maintainer Support

New Rust RFC Proposes Adding Support for Trusted Publishing to Crates.io

Automated Spam Campaign Floods GitHub/NPM with 1000s of Garbage Packages

Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum

New axobject-query Maintainer Faces Backlash Over Controversial Decision to Support Legacy Node.js Versions

Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks - Socket

Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack

The push to ban ransom payments is gaining momentum

More →