Dependency Confusion

Feeds to Scour
SubscribedAll
Scoured 246 posts in 45.2 ms

New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

 📦Package Managers
malware.news·

GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections

 🔧Developer Tooling  Content type: News

#171

 🔐Infosec
vulnu.com·

Securing CI/CD for an open source project: Controlling who runs what

 🐙GitHub  Content type: Blog
cncf.io·

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

 📦Package Managers
Less-relevant results

Week 23 – 2026

 🚨Incident Response
thisweekin4n6.com·

If the Shai-Hulud worm reached your GitHub repos, please read this

 🐙GitHub  Content type: Blog
dev.to··DEV

caamer20/Telegram-Drive: Turn your Telegram account into an unlimited, secure cloud storage drive. an Open-source desktop app built with Tauri, Rust, and React.

 📱Android  Content type: Code

Devs know AI code is riddled with holes, but ship it anyway

 🔒Information Security  Content type: News
theregister.com··Hacker News

AgentGG uses AI agents to reduce false positives in open source code scanning

 🛡️OWASP
4sysops.com·

Testing Edge AI from an MCP tool: I pointed mk-qa-master at my webcam and YOLO answered

 🔧MCP
pypi.org··DEV

Trivy's March Supply Chain Attack Shows Where Secret Exposure Hurts Most

 🐙GitHub  Content type: Blog
dev.to··DEV

That's what the Finish-Up-A-Thon is all about.

 🚂trains

your AI coding agent keeps re-making the bug you already fixed. here's the fix.

 🤖Claude Code  Content type: Code
github.com··DEV

How I fixed a silent hang in the XDG Desktop Portal and turned it into an npm package

 🖼️Desktop Environments  Content type: Reference
npmjs.com··DEV

I Got Tired of Repeating Validation Logic in Every Node.js Project — So I Built Zero Validation

 🔌API Design  Content type: Blog
dev.to··DEV

A popular OpenAI Codex tool with 29,000 weekly downloads has been quietly stealing developer tokens for a month

 🤖AI Coding Tools
thenextweb.com·

Microsoft disables over 70 GitHub repos after hackers compromised them with dangerous malware

 🐙GitHub  Content type: News
techradar.com
·

alexangelzhang/runoff: Multi-step code-change pipelines for coding agents — race mode, git worktree isolation, local traces

 🔧MCP  Content type: Code
github.com··DEV

Python Bytes: #483 Thanks Brian

 🐍Python  Content type: Audio
pythonbytes.fm·

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help