#NPMpackages

2025-11-26

How-To Geek: NPM packages are infected with malware, again. β€œIt should be noted that the issue actually seems to spill over into the Maven ecosystem. Researchers observed that the malicious payload was present in org.mvnpm:posthog-node, a Maven artifact automatically generated from npm packages. This confirms that the automated bridging of software ecosystems can inadvertently bridge security […]

https://rbfirehose.com/2025/11/26/how-to-geek-npm-packages-are-infected-with-malware-again/

N-gated Hacker Newsngate
2025-11-24

πŸ› Oh joy, another thrilling episode of "Whack-a-Mole: Software Edition," where 300+ NPM packages show us that open source security is an oxymoron! πŸŽ‰ struts in with their clipboard and magnifying glass, ready to save the dayβ€”right after the damage is done. πŸ”πŸ“
helixguard.ai/blog/malicious-s

Soatok Dreamseekersoatok@furry.engineer
2025-11-19

Moving Beyond the NPM elliptic Package

If you're in a hurry, head on over to soatok/elliptic-to-noble and follow the instructions in the README in order to remove the elliptic package from your project and all dependencies in node_modules. Art: CMYKat Why replace the elliptic package? Yesterday, the Trail of Bits blog published a post about finding cryptographic bugs in the elliptic library (a Javascript package on NPM) by using the Wycheproof.

soatok.blog/2025/11/19/moving-

#npm #crypto #cryptography #elliptic #security #infosec #cve #mitigation #appsec #javascript #js #npm #npmsecurity #npmpackages

Grahamghalldev
2025-11-11

There's a new release for bgg-client, my JavaScript library for making it easier to use the BoardGameGeek API in your apps!

I've added validation, and have done a lot of work behind the scenes to ensure data integrity, more consistent typing, and better type-safety.

npmjs.com/package/bgg-client

Grahamghalldev
2025-10-28

Just dropped a new release of bgg-client with a breaking change:

An API key from BoardGameGeek is now required.

npmjs.com/package/bgg-client

N-gated Hacker Newsngate
2025-10-27

🎩✨ "Let the little guys in," they say, as if trusting your bank account and ChatGPT with any random npm package is the next big thing! 🀑 Here’s a revolutionary thought: instead of locking down data, let’s just open the floodgates and watch as the personalized web devolves into majestic chaos. πŸš€πŸŒ
arjun.md/little-guys

2025-09-04

A colleague pointed me to this:
reversinglabs.com/blog/ethereu

TLDR: Some #malware in fake #npmpackages downloaded and executes commands stored in an #Ethereum #smartcontract , effectively abusing the contract as a command-and-control server.

#npm #smartcontracts

Ab Sattarabsattar
2025-07-08

i keep forgetting to update packages whom i dont use often, cons of installing packages as standalone, but still way easier than rebuilding packages from source after every major update.

Rene Robichaudnerowild
2025-01-03
Wrappixelwrappixel
2024-10-08

Level up your @react game βš›οΈ with these handpicked 🀝 NPM packages! πŸš€ From state management to UI components, discover tools that'll supercharge your projects. ⚑

πŸ‘‰ wrappixel.com/best-react-npm-p

@reactjs @reactnativeconnection

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst