Red Hat's npm packages compromised, affecting dependent projects
Hacker News·1mo·kurmiashish
Maintainers of Red Hat Insights' JavaScript client packages discovered malicious code injected into their npm distribution. This is a reminder that supply chain attacks target popular dependencies—even those backed by established companies. Indie developers relying on these packages should audit their dependencies and consider the security posture of tools they build on.
Original story
Read the original on Hacker NewsRelated stories

Devtools
Vivix lets you watch JavaScript execute step-by-step in the browserHacker News Show HN·1mo·hlude
Devtools
Capstone: Open-source disassembly framework crosses platforms and architecturesHacker News·1mo·gregsadetsky

Devtools
Open Repair Data Standard aims to unify how repair shops track fixesHacker News·1mo·cassepipe