#npm

[ follow ]
#nodejs
fromnodesource.com
1 day ago
Node JS

15 Recent Node.js Features that Replace Popular npm Packages

Modern Node.js now includes many features previously provided by popular npm packages, reducing dependencies and improving security and maintainability.
fromInfoWorld
4 months ago
Node JS

Node.js 24 drops MSVC support

Node.js 24 brings significant updates to the V8 engine and NPM, crucial for JavaScript development.
Node JS
fromInfoWorld
4 months ago

Node.js 24 drops MSVC support

Node.js 24 brings significant updates to the V8 engine and NPM, crucial for JavaScript development.
Node JS
fromSecurityWeek
1 week ago

GitHub Boosting Security in Response to NPM Supply Chain Attacks

GitHub will require two-factor authentication for local NPM publishing and deploy short-lived, granular tokens plus trusted publishing to mitigate NPM supply-chain attacks.
#malware
Node JS
fromIT Pro
3 months ago

Developers beware: Malware has been found in a dozen popular NPM packages - here's what you need to know

Over a dozen NPM packages have been compromised, delivering malware that allows attackers to control infected machines.
Node JS
fromDeveloper Tech News
4 months ago

Package lurking in npm for six years waits to destroy your work

A malicious npm package, disguised as a legitimate tool, has been uncovered, potentially endangering numerous projects.
The xlsx-to-json-lh package highlights vulnerabilities in package management due to misleading naming.
Node JS
fromIT Pro
3 months ago

Developers beware: Malware has been found in a dozen popular NPM packages - here's what you need to know

Over a dozen NPM packages have been compromised, delivering malware that allows attackers to control infected machines.
Node JS
fromDeveloper Tech News
4 months ago

Package lurking in npm for six years waits to destroy your work

A malicious npm package, disguised as a legitimate tool, has been uncovered, potentially endangering numerous projects.
The xlsx-to-json-lh package highlights vulnerabilities in package management due to misleading naming.
Information security
fromTheregister
1 week ago

GitHub to remove weak security options for npm registry

GitHub is tightening npm publishing security by removing legacy authentication, shortening token lifetimes, enforcing 2FA, and shifting to trusted publishing with short-lived tokens.
Information security
fromThe Hacker News
1 week ago

GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security

GitHub will strengthen npm publishing by requiring FIDO 2FA, short-lived granular tokens, trusted OIDC publishing, and deprecating legacy tokens to prevent supply chain attacks.
Information security
fromZDNET
1 week ago

5 ways to spot software supply chain attacks and stop worms - before it's too late

Shai-Hulud is an ongoing, widespread npm software supply-chain worm attack compromising JavaScript packages and posing a major security crisis for JavaScript developers.
#supply-chain-attack
Web development
from2ality
2 weeks ago

Learning web development: Native package managers

Install an OS package manager to get native shell commands (like curl) that npm cannot provide, enabling non-JavaScript tools for web development tasks.
#software-supply-chain
#supply-chain
fromInfoWorld
1 month ago
Information security

Wave of npm supply chain attacks exposes thousands of enterprise developer credentials

fromInfoWorld
1 month ago
Information security

Wave of npm supply chain attacks exposes thousands of enterprise developer credentials

Web development
from2ality
3 weeks ago

Learning web development: Installing npm packages and bundling

Web apps use npm libraries, tests, and a bundling build step that outputs a single bundle and follows a project file structure.
Information security
fromThe Hacker News
4 weeks ago

Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers

Malicious npm packages used Ethereum smart contracts to hide commands and deliver downloader malware, leveraging GitHub repositories to lure developers and evade detection.
#phishing
fromBleepingComputer
2 months ago

npm 'accidentally' removes Stylus package, breaks builds and pipelines

npm has taken down all versions of the real Stylus library and replaced them with a 'security holding' page, breaking pipelines and builds worldwide that rely on the package.
Web development
Node JS
fromBleepingComputer
2 months ago

North Korean XORIndex malware hidden in 67 malicious npm packages

North Korean threat actors delivered malware through 67 malicious npm packages, affecting over 17,000 downloads.
Node JS
fromInfoQ
3 months ago

Deno 2.3 Now Supports Local NPM Packages

Deno 2.3 enhances local NPM package support and deno compile for streamlined development.
#cybersecurity
fromThe Hacker News
4 months ago
Node JS

Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials

Three malicious npm packages targeting Cursor on macOS are stealing user credentials and distributing harmful upgrades to the software.
Node JS
fromThe Hacker News
5 months ago

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems

Three malicious npm packages disguised as a Telegram bot library have been found, containing SSH backdoors and data exfiltration functionalities.
Node JS
fromThe Hacker News
5 months ago

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems

Three malicious npm packages disguised as a Telegram bot library have been found, containing SSH backdoors and data exfiltration functionalities.
Node JS
fromInfoWorld
3 months ago

NPM adds Workspaces for managing multiple packages

NPM 7.0.0 introduces Workspaces and automatic peer dependency installation, streamlining package management for developers.
fromInfoWorld
1 year ago

Deno boosts dependency management with JSR

Deno 1.42 includes major updates for Node.js and NPM compatibility, enhancing modules such as async_hooks, crypto, and worker_threads for improved performance.
Node JS
Node JS
fromThe Hacker News
5 months ago

Malicious npm Package Targets Atomic Wallet, Exodus Users by Swapping Crypto Addresses

Attackers upload malicious npm packages to target crypto wallet software, enabling them to manipulate transactions covertly.
[ Load more ]