🚨 Malicious update to @ctrl/tinycolor on npm is part of an active supply chain attack hitting 40+ packages across multiple maintainers. Audit & remove affected versions.

Our analysis of the malware: https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages

#NodeJS #JavaScript

Popular Tinycolor npm Package Compromised in Supply Chain At...

Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers

Socket
Newly published NPM versions contain malware · Issue #6776 · valor-software/ngx-bootstrap

Recently published versions 20.0.4, 20.0.5, 20.0.6, 19.0.3 and 18.1.4 contain a post-install script bundle.js that seems to pull various tokens (GitHub, NPM, AWS, GCP) and attempts to exfiltrate cl...

GitHub
Ah, the zenith of web technology in 2023: turn on #JavaScript and #cookies or be doomed to internet obscurity 🤡. Clearly, the Codex of the future has cracked the code of #innovation by demanding we do exactly what we've been doing for decades. 🎉 Well done, #humanity.
https://openai.com/index/introducing-upgrades-to-codex/ #webtechnology #internetobscurity #HackerNews #ngated
Introducing upgrades to Codex

Codex just got faster, more reliable, and better at real-time collaboration and tackling tasks independently anywhere you develop—whether via the terminal, IDE, web, or even your phone.

#Development #Releases
WebKit features in Safari 26.0 · Apple’s browser takes another leap forward https://ilo.im/166wem

_____
#Browser #Safari #WebKit #API #WebDev #Frontend #SVG #HTML #CSS #JavaScript

WebKit Features in Safari 26.0

We’re happy to share with you what’s arriving in Safari 26.0!

WebKit
2025’in En Popüler Yazılım Dilleri

2025’in En Popüler Yazılım Dilleri 💻🚀 Teknolojinin hızla gelişmesiyle birlikte yazılım dilleri de popülerlik kazanıyor veya yerini yeni dillere bırakıyor. 2025 yılı, yapay zeka, veri bilimi, web geliştirme ve mobil uygulamalar için öne çıkan dillerle dolu. İşte 2025’in en popüler yazılım dilleri: 1. Python 🐍 Veri bilimi, yapay zeka, makine öğrenimi ve otomasyon için en

After recent npm supply chain attacks, @pnpm 10.16 adds a setting for delayed dependency updates.

Tools like Taze and npm-check-updates are testing similar “maturity” options, hinting at a cautious new trend in #JavaScript package management.

https://socket.dev/blog/pnpm-10-16-adds-new-setting-for-delayed-dependency-updates #NodeJS

pnpm 10.16 Adds New Setting for Delayed Dependency Updates -...

pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.

Socket