npm 10
- AWS Security Digest #262 - Not private
- Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem
- Backdoored node-ipc npm releases steal developer credentials through DNS queries
- Backdoored Cemu release linked to TanStack and Mistral supply chain campaign
- Shai-Hulud Goes Open Source
- Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
- The Good, the Bad and the Ugly in Cybersecurity – Week 18
- The case for dependency cooldowns in a post-axios world
- CI/CD security: How to secure your GitHub ecosystem
- Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign