How We’re Protecting Our Newsroom From npm Supply Chain Attacks, by @ryansobol.com (@pnpm):

https://pnpm.io/blog/2025/12/05/newsroom-npm-supply-chain-security

#npm #dependencies #security #casestudies

How We're Protecting Our Newsroom from npm Supply Chain Attacks | pnpm

We got lucky with Shai-Hulud 2.0.

Notes 202552 :: Juan B. Rodriguez

run unix on your computer

NPM package with 56,000 downloads compromises WhatsApp accounts

An NPM package with over 56,000 downloads stole WhatsApp credentials, hid its activity, and installed a backdoor.

Security Affairs
ezff

Plain English wrapper for ffmpeg. Stop Googling ffmpeg commands.. Latest version: 0.1.1, last published: a day ago. Start using ezff in your project by running `npm i ezff`. There are no other projects in the npm registry using ezff.

npm

#npm 禁用了(新创建)TOTP 只让使用 passkey,还把 token 的 expire time 限制到 90 天,除非你是 #GitHub 的 partner 可以通过 OIDC 绕过

真恶心啊 🤮 第一次这么支持 ljharb
https://github.com/orgs/community/discussions/174505

feedback on announced plan to kill TOTP · community · Discussion #174505

Select Topic Area Product Feedback Body Personally, I see this as a very harmful decision. It will kill my workflow; having to open a web browser is very disruptive (which is why i still use TOTP a...

GitHub

A five-month spearphishing operation discovered by Socket has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.

Read More: https://www.security.land/npm-registry-weaponized-in-spearphishing-campaign-against-critical-infrastructure/

#SecurityLand #Cybersecurity #Research #NPM #Phishing #CriticalInfrastructure #AiTM #Spearphishing #Dev

npm Registry Abused for Targeted Spearphishing Campaign

A five-month spearphishing operation has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.

Security Land | Decoding the Cyber Threat Landscape

👉 Retrouve les configurations pour mes 15 services (WordPress, Mastodon, Gitea...) ici : 🔗 https://wiki.blablalinux.be/fr/gestion-centralisee-robots-txt-nginx-proxy-manager

C'est cadeau, c'est du partage, et c'est sur le Wiki ! 🐧🚀

#BlablaLinux #SysAdmin #SelfHosted #NPM #RobotsTxt #OpenSource #LogicielLibre

Malicious npm package steals WhatsApp accounts and messages

A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal WhatsApp messages, collect contacts, and gain access to the account.

BleepingComputer

I judge every build tool by how it performs in the context of building a Nix package

Based on this process, I do not like or recommend PNPM

At all

#nix #npm #pnpm #nodejs #javascript #typescript

⚠️ NPM Package With 56K Downloads Caught Stealing WhatsApp Messages

「 The lotusbail npm package presents itself as a WhatsApp Web API library - a fork of the legitimate whiskeysockets/baileys package. With over 56,000 downloads and functional code that actually works as advertised, it's the kind of dependency developers install without a second thought. The package has been available on npm for 6 months and is still live 」

https://www.koi.ai/blog/npm-package-with-56k-downloads-malware-stealing-whatsapp-messages

#npm #malware #whatsapp

NPM Package With 56K Downloads Caught Stealing WhatsApp Messages