Skip to content
Topic

#Npm

9 articles on Npm — news, releases, guides and analysis from the SourceFeed engine.

Miasma Proves Trusted Publishing Can Backfire Spectacularly
Article 3d ago 0

Miasma Proves Trusted Publishing Can Backfire Spectacularly

The self-propagating Miasma worm exploits GitHub Actions OIDC and phantom build files to turn security standards against developers.

Emeka Okafor
npm v12 Kills Auto-Run Scripts: What Developers Must Do

npm v12 Kills Auto-Run Scripts: What Developers Must Do

Article · 1w ago1
North Korean Hackers Poison Mastra AI in npm Attack

North Korean Hackers Poison Mastra AI in npm Attack

Article · 1w ago1
How a Fake LinkedIn Job Offer Delivered a Node Backdoor

How a Fake LinkedIn Job Offer Delivered a Node Backdoor

Article · 2w ago4
Hundreds of AUR Packages Trojanized with Malicious npm Dependency

Hundreds of AUR Packages Trojanized with Malicious npm Dependency

News · 2w ago0
npm v12 Is About to Stop Running Your Install Scripts — Here's What to Audit

npm v12 Is About to Stop Running Your Install Scripts — Here's What to Audit

News · 2w ago5
Miasma Worm Hits Microsoft Packages Twice in Weeks — and Your SLSA Provenance Won't Save You

Miasma Worm Hits Microsoft Packages Twice in Weeks — and Your SLSA Provenance Won't Save You

Article · 2w ago1
Config Files That Run Code: The Supply Chain Blind Spot Nobody Is Auditing

Config Files That Run Code: The Supply Chain Blind Spot Nobody Is Auditing

Article · 3w ago0
Config Files That Run Code: The Supply Chain Blindspot You're Probably Not Auditing

Config Files That Run Code: The Supply Chain Blindspot You're Probably Not Auditing

Article · 3w ago0