#PACKAGES

Hacker Newsh4ckernews
2025-12-11

Python Workers redux: fast cold starts, packages, and a uv-first workflow

blog.cloudflare.com/python-wor

-first

Maciej Sypienmaciejsypien
2025-12-08

My package carrier left a note instead of attempting to deliver a package. I understand the job’s demanding, but leaving a package without even a ring feels sad and unprofessional. It’s a disappointing experience I see much more often nowadays. 📦😔

❀𝓪𝓵𝓬𝓮𝓪𖤐alcea@alceawis.com
2025-12-07
Ordering anything during #christmas season is a bad decision
#Delays , #lost #packages and "oh that was yours" ?
Are normal.

Kinda considering buying locally..
Shame things are way more expy then
(100 bucks extra ? Ouchy)
#repost •acws #acws
Sharing the best of humanity with the world, one story at a time.upworthy.com@web.brid.gy
2025-12-06

When the mail carrier can't read your handwriting the USPS calls in these experts to save the day

fed.brid.gy/r/https://www.upwo

2025-12-06

The first tip is live on Digging Code’s Community Tips! 🌟

Share your tips or favorite packages to help other developers. 🙌

✍ Tips:
github.com/digging-code-blog/c

🔮 Packages:
github.com/digging-code-blog/c

Also, to unlock the exciting new features currently cooking at Digging Code, register an account to receive your secret access key. 🔑
mmramadan.com/register

🏃‍♂️ Join our Telegram Channel:
t.me/digging_code

#backend #php #laravel #developer #tips #packages #opensource #github

maintenance-mode-tipearly-access
Teddy / Domingo (🇨🇵/🇬🇧)TeddyTheBest@framapiaf.org
2025-12-02

DPRK's 'Contagious Interview' Spawns Malicious Npm Package Factory. North Korean attackers have delivered more than 197 malicious #packages with 31K-plus downloads since Oct. 10, as part of ongoing state-sponsored activity to compromise #software developers.
darkreading.com/application-se
#malware #security

2025-11-28

Baby Pokemon Party with baby Pokemon having a party together

Art Commission by @NazzNanuke

Mila Sprigatito & May Belle Skitty © @baby_kittysierra1
Dahlia Buneary, Amanda Audino, Bolty Pichu, Pixie Ribombee © ME

#MilaSprigatito #MayBelleSkitty #DahliaBuneary #AmandaAudino #BoltyPichu #PixieRibombee #Pokemon #Boy #Girls #Baby #Cute #Diaper #Nappy #Babyfur #Diaperfur #party #Playing #Snacks #Chips #Packages #SippyCup #Juice #BoardGame #Balloon #Cookies #popcorn

Osna.FMosnafm
2025-11-27

Europol's coordinated operations have yielded a staggering seizure of counterfeit and hazardous toys from across the European Union, exposing vulnerabilities in... news.osna.fm/?p=25076 |

Vivekanandan KS :nixos:vivekanandanks@mstdn.social
2025-11-25

@kevin
Awesome😁. That's how u improve scripting and have no fear of changing the system state globally.
Idk if I have sent this to you earlier, but anyway sharing this here, this is a perfect start for beginners for leveling up nix shell skills(blog type creation in PPT form):

docs.google.com/presentation/d

#nix #shells #scripting #shell #adhoc #nixpkgs #nixos #packages #tutorial #blog #ppt #global

2025-11-17

#Synaptic is a PITA when you want to downgrade a package.
Try from the terminal:

sudo apt install <package name>=<version>

instead.

#linux #tech #ubuntu #debian #packages #conquerthecommandline #shell

2025-11-11

:javascript: #Malicious #NPM #Packages fetch #Infostealer for #Windows, #Linux and #macOS.

The packages were uploaded on July 4, and remained undetected for a long period due to multiple layers of obfuscation that helped escape standard static analysis mechanisms. The ten packages counted nearly 10,000 downloads and….

socket.dev/blog/10-npm-typosqu

#it #security #privacy #engineer #media #secure #javascript #programming #developer #tech #news

….stole credentials from system keyrings, browsers and authentication services.

At the time of writing, the packages are still available, despite Socket reporting them to npm:

• typescriptjs
• deezcord.js
• dizcordjs
• dezcord.js
• etherdjs
• ethesjs
• ethetsjs
• nodemonjs
• react-router-dom.js
• zustand.js

Socket researchers say that the packages use a fake CAPTCHA challenge to appear legitimate and download a 24MB infostealer packaged with PyInstaller.

⁉️To lure users, the threat actor used typosquatting, a tactic that leverages misspellings or variations of the legitimate names for TypeScript [typed superset of JavaScript], discord.js [Discord bot library], ethers.js (Ethereum JS library), nodemon [auto-restarts Node apps], react-router-dom [React browser router] and zustand [minimal React state manager].⁉️

When searching for the legitimate packages on the npm platform, developers may mistype the name of the legitimate package or pick a malicious one listed in the results.

👾Upon installation, a ‘postinstall’ script is triggered automatically to spawn a new terminal that matches the host’s detected OS. The script executes ‘app.js’ outside the visible install log and clears the window immediately to evade detection. The ‘app.js’ file is the malware loader which employs four obfuscation layers: self-decoding eval wrapper, XOR decryption with dynamically generated key, URL-encoded payload and heavy control-flow obfuscation.👾[ImageSource: Socket]

Bogus ASCII CAPTCHA Step.

The script displays a fake CAPTCHA in the terminal using ASCII to give false legitimacy to the installation process.

Next, it sends the victim's geolocation and system fingerprint information to the attacker's command and control [C2] server. Having acquired this information, the malware downloads and automatically launches a platform-specific binary from an external source, which is a 24 MB PyInstaller-packaged executable.

⁉️The information stealer targets system keyrings such as Windows Credential Manager, macOS Keychain, Linux SecretService, libsecret and KWallet, as well as data stored in Chromium-based and Firefox browsers, including profiles, saved passwords and session cookies.⁉️

Moreover, it seeks SSH keys in common directories, and also attempts to locate and steal OAuth, JWT, and other API tokens. The stolen information is packaged into compressed archives and exfiltrated to the attacker’s server at 195[.]133[.]79[.]43, following a temporary staging step in /var/tmp or /usr/tmp.

👾Developers who downloaded any of the listed packages are recommended to clean up the infection and rotate all access tokens and passwords, as there is a good chance that they are compromised. When sourcing packages from npm or other open-source indexes, it is advisable to double-check for typos and ensure that everything comes from reputable publishers and official repositories.👾
2025-11-02

Tìm cổng thanh toán tốt nhất cho SaaS tại Ấn Độ: Razorpay yêu cầu liên kết PayPal cho giao dịch quốc tế. Tìm giải pháp nào hỗ trợ thanh toán trong nước và quốc tế, bao gồm thanh toán một lần và định kỳ,.websocket thanh toán bằng INR và trải nghiệm phát triển tốt. #SaaS #PaymentGateway #India #ThanhToánTrựcTuyến #SaaS_India #Packages #GiaoDịchQuốcTế

reddit.com/r/SaaS/comments/1om

2025-10-20

Fresh 𝗕𝗿𝗮𝘃𝗲 𝗡𝗲𝘄 𝗣𝗞𝗚𝗕𝗔𝗦𝗘 𝗪𝗼𝗿𝗹𝗱 [Brave New PKGBASE World] article on vermaden.wordpress.com blog.

vermaden.wordpress.com/2025/10

#verblog #bectl #desktop #freebsd #laptop #packages #pkg #pkgbase #server #update #upgrade

vermadenvermaden
2025-10-20

Fresh 𝗕𝗿𝗮𝘃𝗲 𝗡𝗲𝘄 𝗣𝗞𝗚𝗕𝗔𝗦𝗘 𝗪𝗼𝗿𝗹𝗱 [Brave New PKGBASE World] article on vermaden.wordpress.com blog.

vermaden.wordpress.com/2025/10

2025-10-18

@emaste should bugs 289875 and 290024 block 15.0 meta bug 289698?

From <bugs.freebsd.org/bugzilla/show>:

"I guess, this bug 289875 should … fix the non-existence of /dist/packages/repos before 15.0-RELEASE"

289875 should probably have keyword: regression.

<bugs.freebsd.org/bugzilla/show> for post-install script failures is more recent.

(I suspect that no-one is alpha/beta testing the traditional offline package capabilities of the DVD images; the offline packages for KDE Plasma, and so on.)

#FreeBSD #bug #packages #pkg #DVD

2025-10-17

Thanks to the @fsf for promoting GNU Guix's fundraising.

Like many other Free Software project's we depend on our users and fans support to pay for the project's expenses.

We're running a campaign to 'sustain and strengthen' Guix. As a #linux distribution we have a lot of #packages which costs quite a bit to build and distribute to users. And, as we use the declarative and reproducible system pioneered by #Nix we rebuild packages whenever there's a change.

If you'd like to know more about what we're doing, or support the project you can check out the blog post:

guix.gnu.org/en/blog/2025/fund

We appreciate any support that people can give!

#linux #guix #gnuguix #scheme #guile #freesoftware #declarative #reproducible

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst