How We’re Protecting Our Newsroom From npm Supply Chain Attacks, by @ryansobol.com (@pnpm):
https://pnpm.io/blog/2025/12/05/newsroom-npm-supply-chain-security
How We’re Protecting Our Newsroom From npm Supply Chain Attacks, by @ryansobol.com (@pnpm):
https://pnpm.io/blog/2025/12/05/newsroom-npm-supply-chain-security
Ez FFmpeg – Video editing in plain English
#HackerNews #EzFFmpeg #VideoEditing #VideoEditingTools #NPM #JavaScript #TechNews
#npm 禁用了(新创建)TOTP 只让使用 passkey,还把 token 的 expire time 限制到 90 天,除非你是 #GitHub 的 partner 可以通过 OIDC 绕过
真恶心啊 🤮 第一次这么支持 ljharb
https://github.com/orgs/community/discussions/174505
A five-month spearphishing operation discovered by Socket has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.
#SecurityLand #Cybersecurity #Research #NPM #Phishing #CriticalInfrastructure #AiTM #Spearphishing #Dev

A five-month spearphishing operation has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.
👉 Retrouve les configurations pour mes 15 services (WordPress, Mastodon, Gitea...) ici : 🔗 https://wiki.blablalinux.be/fr/gestion-centralisee-robots-txt-nginx-proxy-manager
C'est cadeau, c'est du partage, et c'est sur le Wiki ! 🐧🚀
#BlablaLinux #SysAdmin #SelfHosted #NPM #RobotsTxt #OpenSource #LogicielLibre
I judge every build tool by how it performs in the context of building a Nix package
Based on this process, I do not like or recommend PNPM
At all
⚠️ NPM Package With 56K Downloads Caught Stealing WhatsApp Messages
「 The lotusbail npm package presents itself as a WhatsApp Web API library - a fork of the legitimate whiskeysockets/baileys package. With over 56,000 downloads and functional code that actually works as advertised, it's the kind of dependency developers install without a second thought. The package has been available on npm for 6 months and is still live 」
https://www.koi.ai/blog/npm-package-with-56k-downloads-malware-stealing-whatsapp-messages