Package Managers

Feeds to Scour
SubscribedAll
Scoured 178 posts in 7.5 ms

AUR Packages Attacked by Infostealer

 💚Node.js

npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders

 💚Node.js  Content type: Blog
socket.dev·

Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks

 🐍Python
orca.security·

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

 💚Node.js
securityweek.com·

Release v0.2.99 · anthropics/claude-agent-sdk-python

 🔄GitHub Actions  Content type: Code
github.com·

Package Manager Patents

 🌳Data Structures  Content type: Blog
nesbitt.io·

someone actually leaked the Miasma supply chain attack toolkit source code on github

 🔄GitHub Actions

I Replaced Our Commercial Artifact Registry With a Free One After a 5× Renewal Price Hike.

 💚Node.js  Content type: Blog
medium.com
·

Shai-Hulud Hades PyPI Campaign: 19 Packages Trojanized via Wheel Startup Hooks

 🐍Python  Content type: Blog
socradar.io·

Dependency Execution Intelligence

 🤖Automation
depgaze.xyz··Hacker News

debsecan-mcp v0.1.2 released to PyPI

 🐍Python  Content type: Blog
copyninja.in·

Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System

 💚Node.js  Content type: Blog
aikido.dev·

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

 🔄GitHub Actions  Content type: Blog
about.gitlab.com·

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

 🐍Python
sh.itjust.works·

Linux Kernel 0-Day 🐧, Hades PyPI Worm 🐍, Anthropic Fable 5 🪄

 🐍Python
tldr.tech·

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

 🐍Python
thehackernews.com·

Self-replicating Miasma worm hits 73 Microsoft GitHub repositories in supply chain attack

 💚Node.js  Content type: News
thenextweb.com·

Microsoft desativa 73 repositórios após invasão que visava IA

 💚Node.js
cisoadvisor.com.br·

chore(deps-dev): bump the oxc group across 1 directory with 4 updates…

 🔄GitHub Actions  Content type: Code
github.com
·

Compromised Rust crate onering performs code exfiltration

 🦀Rust  Content type: Blog
aikido.dev··r/rust

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help