Settings

Theme

Big attack on NPM – Shai-Hulud 2.0

about.gitlab.com

2 points by thomasfl 20 days ago · 3 comments

Reader

nycalexander 19 days ago

Made a package (that I needed personally), to easily reinstall all dependencies (using the same versions) in a project and check them using Aikido's safe chain for malware (supported npm, pnpm, bun, and yarn). It also easily switches a project's package manager to another. https://www.npmjs.com/package/eazypm

philipwhiuk 20 days ago

Prior discussion https://news.ycombinator.com/item?id=46032539

thomasflOP 20 days ago

This is a nasty npm attack. It steals API keys and credits.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection