search
npm
Trends
- 1PyPI package MemoryOS accused of hiding credential stealer●"import memos" alone is enough to start a credential stealer. MemoryOS 2.0.34 on PyPI: 149 modules call get_logger() at
Security researchers report that the Python package MemoryOS, version 2.0.34 on PyPI, is trojanized: simply importing the 'memos' module is said to trigger malicious code. Of the package's modules, 149 reportedly call get_logger() at import time, and a modified logger allegedly launches a Go binary, 'sckit', that harvests .npmrc files, Vault tokens, SSH keys and environment secrets. The npm OpenClaw plugin is also named in the report.
- 2101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups▼101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers report that 101 malicious packages published to the npm registry have been found adding developers' WhatsApp accounts to groups without their consent. The packages, disguised as legitimate libraries, harvest phone numbers from developer environments and enroll them into unauthorized WhatsApp groups, likely for spam or scam distribution. The incident highlights ongoing supply chain risks in the npm ecosystem, where attackers continue to abuse open-source package repositories to target software developers.
- 3Critical CVE-2026-102829 flaw reported in simple-git●🚨 CVE-2026-102829 — CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab
A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.
- 485 malicious npm packages found in typosquatting campaign▼(cloudsek.com) Automated Typosquatting Attack on npm Registry: 85 Malicious Packages Target Popular Libraries via Scoped
Cybersecurity firm CloudSEK reports an automated typosquatting campaign on the npm registry, with 85 malicious packages published under the @prime0 scope to impersonate popular libraries and trick developers into installing them. The packages target widely used open-source dependencies, raising concerns about supply chain security and the ease of automating fake package publication at scale.
- 5DirtyBlanket Linux Worm Spreads Through Malicious npm Packages●(safedep.io) DirtyBlanket: Self-Spreading Linux Worm Distributed via Malicious npm Packages Targeting Developers In brie
Security researchers at SafeDep report a self-spreading Linux worm, dubbed DirtyBlanket, distributed through nine malicious npm packages impersonating popular libraries such as Express and React. Once installed, the malware targets developers' Linux machines and propagates further, making supply-chain attacks on the JavaScript ecosystem a renewed concern for developers reviewing dependencies.
Repos
- vercel-labs/scriptc TypeScript-to-Native Compiler
- wy-coliney/jev-browser-use 5–10x faster browser operations: Jev clicks, Codex thinks and verifies. Built at EZCollegeApp.
- tamaratran/fast-jev-compaction Claude Code plugin that replaces the compaction summary with Jev decisions: every tool call and result is scored in one
- Parcha-ai/agentrun The Agentrun Workflow DSL
- WordPress/wordpress-develop WordPress Develop, Git-ified. Synced from git://develop.git.wordpress.org/, including branches and tags! This repository
- nilbuild/page-mascot A mascot that watches the cursor and blinks when you poke it