Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Your ESLint Plugin Installs 205 Packages. 69 Are ESLint.
22+ hour, 24+ min ago (474+ words) npm i -D eslint-plugin-import installs 205 packages. That number is true and almost useless, which is the problem with every dependency-weight argument I have read. 69 of those packages are ESLint itself. Since npm 7, peer dependencies install automatically, so any plugin declaring…...
Shai-Hulud npm worm resurfaces, bypassing security scans
4+ day, 7+ hour ago (80+ words) As outlined in IT Pro, the Shai-Hulud npm worm, previously thought to be neutralized, has reappeared in a new campaign that successfully bypassed npm's recently implemented security measures. The targeted entities are developers and organizations relying on the npm registry…...
Is Shai-Hulud back? Researchers spot 'wormy boy' slipping past npm malware scanning features
4+ day, 23+ hour ago (456+ words) After a 111-day hiatus, Aikido detected a previously-documented Shai-Hulud worm payload in four npm package releases published this week The Shai-Hulud npm worm is back several months after everyone assumed it was dead. Back in May, a compromised maintainer account…...
Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through
6+ day, 2+ hour ago (616+ words) A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can turn into a software supply-chain incident....
npm Supply Chain Worm Returns After Four-Month Dormancy With Same Malicious Payload
6+ day, 1+ hour ago (330+ words) A previously documented Shai-Hulud npm supply-chain worm payload has reportedly reappeared after 111 days of inactivity, using the exact same malicious file linked to the May 19 compromise of hundreds of @AntV package versions. The reactivation raises concerns about registry-level malware detection…...
Shai-Hulud npm Worm Resurfaces After 111 Days and Slips Past Malware Scanning
6+ day, 11+ min ago (672+ words) A familiar npm worm has returned after more than three months of silence, carrying the same malicious file linked to an earlier supply-chain incident. The reappearance shows how a known threat can regain access to developer environments when it is…...
Shai-Hulud Malware Returns to npm Unchanged, 111 Days After Its Hash Was Fingerprinted
5+ day, 21+ hour ago (507+ words) Four packages is a small blast radius next to the 639 malicious versions pushed during the May campaign. The significance sits elsewhere. npm rolled out publish-time scanning in July, a control that briefly holds new publications for automated analysis before they…...
A Shai-Hulud npm payload came back 111 days later
6+ day, 17+ hour ago (396+ words) Advanced AppSec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Since then, npm has introduced publish-time malware scanning. So you can imagine my surprise when I was going through our triage queue this morning…...
JSCeal Hides Crypto Malware in V8 Bytecode
6+ day, 20+ hour ago (764+ words) Why AI Agent Sandboxes Are Failing Security Tests Berlin Ransomware Leak Exposes State Secrets Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure Security Affairs newsletter Round 593 by…...
Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic
1+ week, 21+ hour ago (517+ words) Rescana Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic Technical Analysis of Malware/TTPs The Ted backdoor is not a vulnerability in the official HAProxy codebase, but rather a malicious plugin…...