
314 npm packages hit in new supply chain attack campaign
Hacker News·4mo·theanonymousone
A coordinated attack compromised over 300 npm packages in what researchers are calling "Mini Shai-Hulud," marking a serious escalation in npm ecosystem security. For developers pulling dependencies into production, this underscores the ongoing risk of trusting package registries without additional verification—especially for smaller, less-monitored packages that may slip through standard security checks.
Original story
Read the original on Hacker NewsRelated stories
Devtools
RePlaya: self-hosted session replay with live tailing, no third-party data sharingHacker News Show HN·3mo·shikhar

Devtools
Open Repair Alliance publishes data standard for right-to-repair trackingHacker News·3mo·cassepipe

Devtools
Opstan brings decentralized social networking to a proof-of-work blockchainHacker News Show HN·3mo·opstan