npm

8 stories and discussions about npm, aggregated from every source we track.

1.

Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account

5 points•dbremner•about 2 months ago•0 comments
2.

Nine fake Express and React packages on npm run a Linux worm at install time. It installs a Tor backdoor and spreads through SSH, AUR packages, and npm tokens.

2 points•Yogthos•about 23 hours ago•0 comments
3.
2 points•Kuyawa•6 days ago•1 comment•
4.

The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are…

2 points•joshcsimmons•7 days ago•0 comments•
5.

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in…

2 points•sbulaev•10 days ago•0 comments•
6.

Nine fake Express and React packages on npm run a Linux worm at install time. It installs a Tor backdoor and spreads through SSH, AUR packages, and npm tokens.

1 points•thunderbong•1 day ago•0 comments•
7.

The left-pad incident: in 2016 one npm unpublish of an 11-line package broke Babel and thousands of builds for 2.5 hours. How it happened and what changed.

1 points•axrisi•1 day ago•0 comments
8.

Nine fake Express and React packages on npm run a Linux worm at install time. It installs a Tor backdoor and spreads through SSH, AUR packages, and npm tokens.

1 points•kunalsin9h•1 day ago•0 comments•

Related topics