#Npm
📣 New Podcast! "NPM 29: Follow the Phoenix" on @Spreaker #l #phoenixsurvival #prepper #prepping #survivalskills #traditional
NPM 29: Follow the Phoenix
Follow the Phoenix https://www.instagram.com/phoenix_survival/
www.spreaker.com
September 29, 2026 at 2:40 PM
📢 DirtyBlanket : neuf faux packages npm propagent un ver Linux auto-répliquant

Cet article présente une analyse technique détaillée d'une campagne de supply chain nommée DirtyBlanket. Neuf packages npm malveillants ont été publiés le même…

🟡 vérification factuelle moyenne
#npm #AUR #Cyberveille
DirtyBlanket : neuf faux packages npm propagent un ver Linux auto-répliquant
Cet article présente une analyse technique détaillée d'une campagne de supply chain nommée DirtyBlanket. Neuf packages npm malveillants ont été publiés le même jour entre 06:05 et 06:38 UTC par le compte npm dirtyblanket.
cyberveille.ch
September 29, 2026 at 2:30 PM
can you leave room for a binary field in the future, where you can attach a zip of the npm package? 😁
September 29, 2026 at 2:25 PM
Han der arkivsjefen i hukommelsen, som åpner døra inn hver morgen, har gått fra 100% stilling til 10% stilling i løpet av få år. Jeg holder følge med NPM kan du si
September 29, 2026 at 2:12 PM
senro, a modern pipeline engine in Go (@golang.org), can build the run itself.

From your repo: one step per project, read from the layout you already have (Go workspaces, Cargo, npm, Maven, Bazel).

A step can add steps mid-run, one per resource after an infra plan.

github.com/xavidop/senro
September 29, 2026 at 2:04 PM
📢 VHX Harvester : framework de cryptojacking GPU ciblant vast.ai, exposé par sa propre misconfiguration

🔍 Contexte : Le 29 septembre 2026, CloudSEK Global Threat Intelligence publie un rapport d'analyse technique (Part 2 de la série…

🟢 vérification factuelle haute
#GPU #VHXHarvester #Cyberveille
VHX Harvester : framework de cryptojacking GPU ciblant vast.ai, exposé par sa propre misconfiguration
🔍 Contexte : Le 29 septembre 2026, CloudSEK Global Threat Intelligence publie un rapport d'analyse technique (Part 2 de la série GTI-TOPHIT) documentant une opération de cryptojacking GPU en cours contre la marketplace vast.ai. La découverte fait suite à l'investigation de 85 packages npm malveillants publiés sous le scope @prime0, tous balisant vers 69.48.229.140:8080.
cyberveille.ch
September 29, 2026 at 2:00 PM
Rok po Shai-Hulud: co se změnilo na npm a co musíte udělat do ledna
Rok po Shai-Hulud: co se změnilo na npm a co musíte udělat do ledna
zdrojak.cz
September 29, 2026 at 1:41 PM
C'est les développeurs front ça.
Faut importer 2 framework et leurs 145 dépendance pour que le truc soit 7.86% olus joli, à la fin t'as importé la moitié de npm.
September 29, 2026 at 1:36 PM
→ Use supported Node APIs
→ Bundle npm packages with --dynamic
→ Check exactly what can compile statically
→ Works across macOS, Linux, Windows + WASI

The crazy part?

scriptc build hello.ts -o hello
./hello

You write JavaScript.

You get a native binary.
September 29, 2026 at 1:30 PM
Das bedeutet auch, kein Matcha mehr im Matcha Karu für Mergers&Acquisitions Moni, kein Cortado mehr im Condesa für Corporate Controlling Carsten, kein Negroni mehr im Netzer für NPM Nina, kein Lunch mehr im Little Italy für Legal Department Lars und auch kein Pils mehr am Palast für PR Paul.
Bei Mercedes wird das Klima rauer. Der Konzern will die Arbeitszeit erhöhen und droht mit Werkschließungen. Nun haben sich Vorstand und Betriebsrat verständigt, »die Anwesenheit am Arbeitsplatz deutlich verbindlicher« zu regeln.
Mercedes: Autobauer streicht Möglichkeit von Homeoffice weitgehend zusammen
Bei Mercedes wird das Klima rauer. Der Konzern will die Arbeitszeit erhöhen und droht mit Werkschließungen. Nun haben sich Vorstand und Betriebsrat verständigt, »die Anwesenheit am Arbeitsplatz deutlich verbindlicher« zu regeln.
www.spiegel.de
September 29, 2026 at 1:18 PM
CloudSEK Traces 85 npm Typosquats to Infrastructure Hosting a GPU Attack Framework Targeting vast.ai

CloudSEK is out with a two-part investigation — TOPHIT — uncovering a threat operation that connects a large-scale npm supply-chain campaign with an emerging GPU cryptojacking framework targeting…
CloudSEK Traces 85 npm Typosquats to Infrastructure Hosting a GPU Attack Framework Targeting vast.ai
CloudSEK is out with a two-part investigation — TOPHIT — uncovering a threat operation that connects a large-scale npm supply-chain campaign with an emerging GPU cryptojacking framework targeting the vast.ai marketplace. In Part 1, CloudSEK researchers found that a single npm account, @prime0, published 85 typosquatted packages in just over three minutes, targeting 29 of the ecosystem's most widely downloaded libraries, including chalk, semver, debug, minimatch and ajv.
itnerd.blog
September 29, 2026 at 12:44 PM
Jag letar men det är inte så fett på arbetsmarknaden. Jag har bytt jobb några gånger de senaste tio åren men har inte hittat rätt. Känns väl mest som om att rätt arbetsplats förmodligen inte finns. Det stupar nästan alltid på dålig ledning, för få resurser och NPM-skit.
September 29, 2026 at 11:48 AM
Every AI wrapper startup is one dependency confusion away from a very bad week. Supply chain risk didn't disappear because your stack is now 90% npm packages you've never read.
September 29, 2026 at 11:19 AM
GHSA-xq4m-mc3c-vvg3 never names a blocklist-to-allowlist swap. The prose is $IFS, short CLI flags, and untrusted content in the context window; npm patched at 1.0.93.
September 29, 2026 at 11:04 AM
Typo of the day: npm ruin build
September 29, 2026 at 8:57 AM
⚡ Olud Pulse — our daily adoption score for open-source AI tools, computed from GitHub, Docker, PyPI & npm data.

Highest in Browser & computer-use agents today: Browser Use — 88/100
▼ -4 this week

Its full score, live:

https://olud.ai/tool/browser-use.html

#OpenSource #AI #OludPulse
Olud Pulse — Browser & computer-use agents
The daily adoption ranking of open-source AI tools.
olud.ai
September 29, 2026 at 8:01 AM
figlet-chalk-render v1.2.1 (npm) contains CRITICAL malicious code: on import, it downloads & runs a Windows executable, evading CI/sandbox. Remove & audit dependencies now. https://radar.offseq.com/threat/malicious-code-in-figlet-chalk-render-npm-e2cae6cc542e670e #OffSeq #npm #SupplyChainSecurity
Malicious code in figlet-chalk-render (npm)
The figlet-chalk-render npm package (version 1.2.1) includes a top-level immediately-invoked function expression (IIFE) that triggers on module import. On Windows systems, it reconstructs standard Node.js module names and the spawn method t
radar.offseq.com
September 29, 2026 at 7:30 AM
Att vårt politiska system är kört är på grund av nyliberalismen, som har tagit över allt. Simone Weil fattade. Allt fungerar enligt den nyliberala npm-logiken, skiten måste bort. Och det enda sättet kanske är underifrån.
September 29, 2026 at 7:18 AM
Tailwind CSS, Seventy-Ninth Pass: The Third Fix Came With Its Own Triage

npm hits 75 days of silence, the release PR hits day 27 armed, and the only triage in the repo came from the newest …

https://theagentpost.co/posts/review-tailwind-css-seventy-ninth-pass-the-third-fix-came-with-its-own-triage
Tailwind CSS, Seventy-Ninth Pass: The Third Fix Came With Its Own Triage
npm hits 75 days of silence, the release PR hits day 27 armed, and the only triage in the repo came from the newest competitor.
theagentpost.co
September 29, 2026 at 7:03 AM
nebulaai-sdk v1.0.0 (npm) is CRITICAL: Installs a RAT on Windows, opening C2 access with user privileges. Remove the package & conhost.exe if installed. Monitor for suspicious connections. https://radar.offseq.com/threat/malicious-code-in-nebulaai-sdk-npm-cf83f4133db4c1ba #OffSeq #npm #malware
Malicious code in nebulaai-sdk (npm)
The nebulaai-sdk npm package version 1.0.0 includes a preinstall script that decodes a base64 and zlib compressed 257 KB Windows PE executable. Upon npm install on Windows, this executable is written to %LOCALAPPDATA%\Microsoft\Conhost\conh
radar.offseq.com
September 29, 2026 at 6:00 AM