lcamtuf, to random

deleted_by_author

  • Loading...
  • mjgardner,
    @mjgardner@social.sdf.org avatar

    @lcamtuf Please please please let this be the next #npm left-pad rug pull

    schizanon, (edited ) to webdev
    @schizanon@mas.to avatar

    > You can't get faster than No Build

    "The state of the art is no longer in finding more sophisticated ways to build JavaScript or CSS. It's not to build at all. To lean on HTTP/2 and the now universal support for import maps to avoid bundling."

    https://world.hey.com/dhh/you-can-t-get-faster-than-no-build-7a44131c

    schizanon, to node
    @schizanon@mas.to avatar

    Arguably optimizing for 0-dependencies packages is kinda wrong in some cases, because if you use 100 packages, each with 0 dependencies, then most likely there is going to be a decent amount of code duplication in there, and the packages won't necessarily work well together.

    #npm #js #javaScript #npmjs #webDev

    williballenthin, to node
    @williballenthin@mastodon.social avatar

    is it malware if the #npm package name tells you itโ€™s stealing /etc/passwd?

    0x58, to Cybersecurity

    ๐Ÿ“จ Latest issue of my curated #cybersecurity and #infosec list of resources for week #39/2023 is out! It includes the following and much more:

    โž ๐Ÿ”“ #GitHub repos bombarded by info-stealing commits masked as #Dependabot
    โž ๐Ÿ‡ฏ๐Ÿ‡ต ๐Ÿ’ธ #Sony Investigating After Hackers Offer to Sell Stolen Data
    โž ๐Ÿ”“ #BORN Ontario child registry #databreach affects 3.4 million people
    โž ๐Ÿ‡ญ๐Ÿ‡ฐ ๐Ÿ”“ Personal data of 25,000 Hongkongers at risk after #cyberattack against consumer watchdog, up from earlier estimate of 8,000
    โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ”“ National Student Clearinghouse data breach impacts 890 #schools
    โž ๐Ÿ‡จ๐Ÿ‡ฆ โœˆ๏ธ #AirCanada discloses data breach of employee and 'certain records'
    โž ๐Ÿ‡ฐ๐Ÿ‡ต ๐Ÿ‡ช๐Ÿ‡ธ North Korean hackers posed as #Meta recruiter on #LinkedIn
    โž ๐Ÿ‘ฅ ShadowSyndicate: A New #Cybercrime Group Linked to 7 #Ransomware Families
    โž ๐Ÿ‡ท๐Ÿ‡บ โœˆ๏ธ Russian flight booking system suffers โ€˜massiveโ€™ cyberattack
    โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡บ๐Ÿ‡ธ Chinese hackers stole emails from US State Dept in #Microsoft breach, Senate staffer says
    โž ๐Ÿ‡จ๐Ÿ‡ณ Chinese Hackers TAG-74 Targets South Korean Organizations in a Multi-Year Campaign
    โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿš€ Ukrainian Military Targeted in Phishing Campaign Leveraging #Drone Manuals
    โž ๐Ÿฅท๐Ÿป ๐Ÿ’ฐ Hackers steal $200M from #crypto company #Mixin
    โž ๐Ÿ‡ณ๐Ÿ‡ฌ โš–๏ธ Nigerian man pleads guilty to attempted $6 million BEC email heist
    โž ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ ShinyHunters member pleads guilty to $6 million in data theft damages
    โž ๐Ÿ‡จ๐Ÿ‡ณ #China-Linked Budworm Targeting Middle Eastern #Telco and Asian Government Agencies
    โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿšช Backdoored firmware lets China state hackers control #routers with โ€œmagic packetsโ€
    โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‘ฎ๐Ÿปโ€โ™‚๏ธSecurity researcher warns of chilling effect after feds search phone at #airport
    โž ๐Ÿฆ  โ—๏ธFBI Warns Organizations of Dual Ransomware, Wiper Attacks
    โž ๐Ÿค– ๐Ÿฆ  #Bing Chat responses infiltrated by ads pushing #malware
    โž ๐Ÿฅ ๐ŸŽฃ Red Cross-Themed #Phishing Attacks Distributing DangerAds and AtlasAgent Backdoors
    โž ๐Ÿฅท๐Ÿป ๐Ÿ #SSH keys stolen by stream of malicious #PyPI and #npm packages
    โž ๐Ÿฆ ๐ŸŽ  New Variant of #Banking #Trojan BBTok Targets Over 40 Latin American Banks
    โž ๐Ÿฆ  ๐Ÿšช #Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics
    โž ๐Ÿš€ #Sysdig Launches Realtime Attack Graph for Cloud Environments
    โž ๐Ÿ› ๐Ÿ“จ Critical vulnerabilities in #Exim threaten over 250k #email servers worldwide
    โž ๐Ÿ”“ Progress warns of maximum severity WS_FTP Server vulnerability
    โž ๐Ÿฉน ๐Ÿ”ฅ #Google fixes fifth actively exploited Chrome zero-day of 2023
    โž ๐Ÿฉน ๐Ÿ #macOS 14 #Sonoma Patches 60 #Vulnerabilities
    โž ๐Ÿฉน ๐ŸฆŠ #Firefox 118 Patches High-Severity Vulnerabilities
    โž ๐Ÿคซ โœ… Google quietly corrects previously submitted disclosure for critical #webp 0-day
    โž ๐Ÿ‘€ ๐Ÿ‡ช๐Ÿ‡ฌ 0-days exploited by commercial surveillance vendor in #Egypt

    ๐Ÿ“š This week's recommended reading is: "Philosophy of Cybersecurity" by @LukaszOlejnik and Artur Kurasinski

    Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

    https://infosec-mashup.santolaria.net/p/infosec-mashup-week-392023

    voxpelli, to programming
    @voxpelli@mastodon.social avatar

    FYI โ€“ Iโ€™m available for / / conference talks / shorter gigs (1-2 days at a time)

    Iโ€™m right now primarily focusing on my own projects but happy to share my experience with others + never wrong to refill the wallet a bit.

    Topics Iโ€™m extra thrilled about:

    ben, to node
    @ben@hardill.me.uk avatar

    Anybody know how to stop npm using "git+ssh://git@github.com/org/repo" URLs in package-lock.json files even if the dependency is using "https://github.com/org/repo"

    #npm #GitHub

    tanepiper, (edited ) to random
    @tanepiper@tane.codes avatar

    LOL another supply chain attack in #NPM using postinstall scripts - an issue I REPORTED TO NPM OVER 6 YEARS AGO BUT THE CLOSED AS WONTFIX

    https://www.cyber-oracle.com/p/malicious-npm-packages-strike-again

    (The POC I wrote to prove it - https://github.com/tanepiper/steal-ur-stuff)

    #infosec #security

    chrisonline, to windows
    @chrisonline@androiddev.social avatar

    Manage software programs on your windows device with the awesome tool WinGetUI!

    A graphical user interface to manage packages from the most common package managers for windows, such as Winget, Scoop, Chocolatey, Pip, Npm and .NET Tool.

    https://www.marticliment.com/wingetui

    Martรญ Climent seems is not on Mastodon so I can't link him.
    Here you will see his other projects:
    https://www.marticliment.com/#contact

    #windows #wingetui #linux #packagemanager #winget #software #scoop #chocolatey #pip #npm

    bitexpert, to node German
    @bitexpert@rheinneckar.social avatar
    kaiserkiwi, to webdev German
    @kaiserkiwi@corteximplant.com avatar

    This is actually a pretty awesome (but lengthy) post about Bun and why you probably shouldn't jump on the train already.

    Bun hype. How we learned nothing from Yarn
    https://dev.to/thejaredwilcurt/bun-hype-how-we-learned-nothing-from-yarn-2n3j

    #Coding #WebDev #JavaScript #NPM #Bun #BunJS #Yarn #ESBuild #Node #NodeJS

    YourAnonRiots, to infosec Japanese
    @YourAnonRiots@mstdn.social avatar

    Beware of npm imposters! 14 fraudulent packages found in the registry, posing as legit tools. They aim to steal your Kubernetes configs and SSH keys.

    https://thehackernews.com/2023/09/fresh-wave-of-malicious-npm-packages.html

    #infosec #cybersecurity #technews

    kkarhan,
    @kkarhan@mstdn.social avatar

    @YourAnonRiots see that's the problem with #npm: It's the equivalent of using #eD2k to host #Software...

    melroy, to javascript
    @melroy@mastodon.melroy.org avatar
    decaplanet, to typescript

    @deno_land I tried Deno real quick. I think itโ€™s actually much better than I thought. ๐Ÿ‘

    #TypeScript #JavaScript #Deno #npm

    stvfrnzl, to node
    @stvfrnzl@mastodon.online avatar

    Hey @astro, I tried running a brand new Astro project with but there seems to be an issue when installing the dependencies?

    When running "npm run dev" it cannot find the "astro" command. When installing it with everything works fine and as expected (no error during dependency install). ๐Ÿคทโ€โ™‚๏ธ

    Screenshot of text prompts during the installation process of Astro with yarn. No errors, everything going smooth!

    mez, to node
    @mez@mastodon.nz avatar

    nom audit fix just โ€œimprovedโ€ my vulnerabilities from

    36 vulnerabilities (1 low, 10 moderate, 20 high, 5 critical)
    to
    36 vulnerabilities (1 low, 7 moderate, 18 high, 10 critical)

    Cool cool cool, so my critical issues have doubled. Are those new or did it just shuffle things around?

    #npm #webDev

    DavidAnson, to node
    @DavidAnson@mastodon.social avatar

    I had a bad experience with npm-shrinkwrap.json recently. I read the documentation and took care, but it wasnโ€™t enough. Based on that, my current opinion is that #npm #shrinkwrap is unusable for its intended purpose. That seems absurd and I am happy to learn what Iโ€™m doing wrong. Hereโ€™s a brief summary:

    https://gist.github.com/DavidAnson/39b0eed160f7ce481c92e24a651b5d6f

    AstraKernel, to node

    ๐ŸชฒNPM Package Masquerading as Email Validator Contains C2 and Sophisticated Data Exfiltration

    https://blog.phylum.io/npm-emails-validator-package-malware/

    #npm #javascript #typescript #infosec #nodejs

    iamdtms, to webdev
    @iamdtms@mas.to avatar

    Actually what is the best way to show an #MP4 video in #HTML #container?
    Regarding:

    adam, to opensource

    Meta, a near trillion-dollar mega corp, is bullying #opensource devs by spamming cease-and-desists (including to 15-year-olds instead of praising their genius) to unfairly eliminate competition to their #whatsapp #npm package (complete details here: https://i.imgur.com/FJZakpH.png) @eff

    skwee357, to node
    @skwee357@mstdn.social avatar

    Every time I do a change on the website, which is not content, I also try to update the dependencies. Otherwise I might end up with a huge mess in the future.

    How often do you update your dependencies?

    #npm #dependencies

    markstos, to programming
    @markstos@urbanists.social avatar

    Parts of the #NodeJS #NPM repo are full of essentially private forks that are polluting the public commons. Here, the main project, passport-saml is well-maintained and up-to-date with security fixes.

    The foxden fork, as an example, removed the README and changed the license to "unlicensed" (which I'm not sure is even legal). Notice how most forks don't even bother to update the description to give a hint why there for is different.

    Minimally useful for users.

    louislang, to node
    @louislang@fosstodon.org avatar

    Nine #npm packages uncovered by phylum.io communicating with command and control infrastructure in what appear to be continuing targeted attacks.

    #javascript #malware #infosec #node #opensource

    https://blog.phylum.io/sophisticated-highly-targeted-attacks-continue-to-plague-npm/

    cadey, to javascript
    @cadey@pony.social avatar

    Introducing nixexpr: Nix expressions for JavaScript

    https://xeiaso.net/blog/nixexpr

    #nix #javascript #nodejs #npm #cursed

    seanmonstar, to rust
    @seanmonstar@masto.ai avatar

    Those complaining about #rust cargo and dependencies have never used npm (or forgotten).

    skwee357,
    @skwee357@mstdn.social avatar

    @seanmonstar #rust cargo feels like a breath of fresh air compared to #javascript #npm

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines