MikeTrendsTrends right now

search

NPM

Trends

  1. 1
    PyPI package MemoryOS accused of hiding credential stealerโ—"import memos" alone is enough to start a credential stealer. MemoryOS 2.0.34 on PyPI: 149 modules call get_logger() atMmastodonTechnologyCybersecurity19 d ago

    Security researchers report that the Python package MemoryOS, version 2.0.34 on PyPI, is trojanized: simply importing the 'memos' module is said to trigger malicious code. Of the package's modules, 149 reportedly call get_logger() at import time, and a modified logger allegedly launches a Go binary, 'sckit', that harvests .npmrc files, Vault tokens, SSH keys and environment secrets. The npm OpenClaw plugin is also named in the report.

  2. 2
    New theory argues AI does not actually existโ—Its a new dawn โ€“ its a new day! And I am feeling good. https:// youtu.be/xlNpmSN7mRg There is a rather interesting theorMmastodonTechnologyAI27 d ago

    A widely shared post pairs Nina Simone's 'Feeling Good' with a discussion of an underexamined theory in the AI debate: that artificial intelligence does not, logically speaking, actually exist. The post links to a YouTube video laying out the argument, and is drawing attention as public discussion of AI technology remains heated.

  3. 3
    New site ranks data visualisation tools dailyโ—Show HN: Dataviz, ranked daily from GitHub, NPM, PyPI and CRAN Article URL: https:// awesomedataviz.com/ Comments URL: hMmastodonBusinessStartups22 d ago

    A new website called Awesome Dataviz has launched, ranking data visualisation libraries and tools on a daily basis using metrics drawn from GitHub, NPM, PyPI and CRAN. The launch was shared on Hacker News as a Show HN post, drawing modest engagement with a small number of points and few comments so far.

  4. 4
    New site ranks data visualisation tools daily across package ecosystemsโ—Show HN: Dataviz, ranked daily from GitHub, NPM, PyPI and CRANYhn112 d ago

    A new website called Awesome Dataviz ranks data visualisation libraries and tools daily, drawing signals from GitHub, NPM, PyPI and CRAN. The project was shared on Hacker News by its creator, Javier Luraschi, inviting feedback from the developer community. The rankings aim to help developers and analysts discover which visualisation libraries are currently gaining traction across the main open-source package ecosystems.

  5. 5
    Progress Software discloses SSRF flaw in Sitefinity Next.js SDKโ—CVE-2026-92931: Progress Software reports a server-side request forgery flaw in its Sitefinity Next.js SDK npm package.MmastodonTechnologyCybersecurity12 d ago

    Progress Software has disclosed CVE-2026-92931, a server-side request forgery vulnerability in the Sitefinity Next.js SDK npm package. According to the advisory, a remote attacker could trick the server into making requests to an attacker-controlled host, potentially exposing sensitive information. Affected versions reportedly begin with 15.1.8326, and developers using the package are being urged to review their installations.

  6. 6
    ChainDrop attack poisons npm packages via hijacked maintainer accountโ—ChainDrop: attackers hijacked a maintainer's GitHub account and shipped poisoned npm releases with valid provenance. 400MmastodonTechnologySoftware321 h ago

    Security researchers are warning about a supply chain attack dubbed ChainDrop, in which attackers took over a package maintainer's GitHub account and published malicious npm releases carrying valid cryptographic provenance. The compromised releases reportedly touched around 400 packages with an estimated two billion weekly downloads. Commentators say the attack shows that provenance attestation works technically but cannot protect against a trusted account being compromised in the first place.

  7. 7
    101 Malicious npm Packages Found Adding Developers to WhatsApp Groupsโ–ผ101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consentโœ‰newsTechnologySoftware7 d ago

    Security researchers have identified 101 malicious npm packages that secretly add developers' WhatsApp accounts to groups without their consent. The packages pose as legitimate tools to trick developers into installing them, after which they abuse WhatsApp's click-to-chat functionality to enroll victims in groups, potentially for scam or spam purposes. Developers are advised to audit dependencies and remove any affected packages.

  8. 8
    New site ranks data visualisation tools dailyโ—Show HN: Dataviz, ranked daily from GitHub, NPM, PyPI and CRAN https://awesomedataviz.com/ # HackerNews # Tech # DataVizMmastodonTechnology22 d ago

    A new website called Awesome Dataviz has launched, ranking data visualisation libraries and tools each day based on activity across GitHub, NPM, PyPI and CRAN. The launch was shared as a Show HN submission, where it drew modest early attention from the developer community, with commenters weighing in on the usefulness of daily cross-ecosystem rankings for picking charting and plotting libraries.

  9. 9
    85 malicious npm packages found in typosquatting campaignโ–ผ(cloudsek.com) Automated Typosquatting Attack on npm Registry: 85 Malicious Packages Target Popular Libraries via ScopedMmastodonTechnologyCybersecurity18 d ago

    Cybersecurity firm CloudSEK reports an automated typosquatting campaign on the npm registry, with 85 malicious packages published under the @prime0 scope to impersonate popular libraries and trick developers into installing them. The packages target widely used open-source dependencies, raising concerns about supply chain security and the ease of automating fake package publication at scale.

  10. 10
    DirtyBlanket Linux Worm Spreads Through Malicious npm Packagesโ—(safedep.io) DirtyBlanket: Self-Spreading Linux Worm Distributed via Malicious npm Packages Targeting Developers In brieMmastodonTechnologyCybersecurity18 d ago

    Security researchers at SafeDep report a self-spreading Linux worm, dubbed DirtyBlanket, distributed through nine malicious npm packages impersonating popular libraries such as Express and React. Once installed, the malware targets developers' Linux machines and propagates further, making supply-chain attacks on the JavaScript ecosystem a renewed concern for developers reviewing dependencies.

  11. 11
    Critical CVE-2026-102829 flaw reported in simple-gitโ—๐Ÿšจ CVE-2026-102829 โ€” CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enabMmastodonTechnologyCybersecurity07 d ago

    A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.

Repos