Skip to main content
Scour
Browse
Getting Started
Login
Sign Up
You are offline. Trying to reconnect...
Close
Copied to clipboard
Close
Unable to share or copy to clipboard
Close
safedep.io
5
posts in the last 30 days
Dependency
cooldown
using the
publish
age as a signal for package resolution
safedep.io
·
1w
·
r/programming
@
fairwords
npm packages compromised by a
self-propagating
credential worm - steals tokens, infects other packages you own, then crosses to PyPI
safedep.io
·
2w
·
Hacker News
,
r/Malware
,
r/programming
Thirty-Six Malicious npm
Strapi
Packages Deploy Redis RCE, Database Theft, and Persistent
C2
safedep.io
·
3w
·
Hacker News
March 2026 was a
rough
month for open source supply
chain
security
safedep.io
·
3w
·
r/webdev
axios 1.14.1 and 0.30.4 on npm are
compromised
- dependency injection via stolen
maintainer
account
safedep.io
·
3w
·
Hacker News
,
r/javascript
,
r/programming
Log in to enable infinite scrolling
Keyboard Shortcuts
Navigation
Next / previous item
j
/
k
Open post
o
or
Enter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
g
h
Interests
g
i
Feeds
g
f
Likes
g
l
History
g
y
Changelog
g
c
Settings
g
s
Browse
g
b
Search
/
Pagination
Next page
n
Previous page
p
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc
Press
?
anytime to show this help