frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

NPM Packages Attacks

2•carlostkd•6h ago
You should read this before you install any #npm package. Because the author mentioned the taking advantage of the #AI #hallucinations but forgot that attackers can also "instruct" AIs to make reference to a malicious package

https://blog.gaborkoos.com/posts/2026-05-29-How-to-Evaluate-an-npm-Package-2026-Edition/?utm_source=reddit&utm_medium=social&utm_campaign=how-to-evaluate-an-npm-package-2026-edition&utm_content=r_netsec

#infosec #cybersecurity #ethicalhacking #news #privacy

Comments

gitgud•3h ago
Article and this post seems to be AI generated… but this is a good quote

> AI coding assistants hallucinate package names. They confidently suggest npm install some-plausible-sounding-package for packages that do not exist. Attackers monitor those hallucinations and register the names - a technique now called slopsquatting

Slopsquatting is a hilarious name for this

NPM Packages Attacks

2•carlostkd•6h ago•1 comments

Ask HN: Any advice on how to learn good software architecture practices?

13•jimsojim•20h ago•8 comments

Ask HN: If I cancel Codex today whats the next best local inference agent?

8•Bulbasaur2015•19h ago•4 comments

Ask HN: What's the hardest problem you've ever solved?

8•chistev•3h ago•3 comments

Ask HN: How is your org managing PR review load as AI multiplies code output?

8•meteor333•15h ago•8 comments

Ask HN: What Are You Thankful For?

6•chistev•3h ago•1 comments

FYI: Dreamina is shady; do not use

4•ronyeh•17h ago•0 comments

Ask HN: What Is an "AI Engineer"?

17•seattle_spring•1d ago•29 comments

Ask HN: Does Claude Code remove the need for so many front-end frameworks?

10•ex-aws-dude•1d ago•11 comments

Ask HK: How are you building AI apps today?

7•Mnexium•22h ago•5 comments

Ask HN: I found out that I'm about to be laid off. How do people find jobs?

21•wwwthrowaway256•1d ago•16 comments

Ask HN: Is anyone working at least 4 hours daily on an Apple Vision Pro?

152•widenrun•4d ago•108 comments

C++ CLI for folder encryption with AES-256-GCM and USB-based key loading

2•nextma•2d ago•0 comments

Garnix, the Nix CI, is shutting down

12•cinericius•1d ago•4 comments

Ask HN: How do you feel about posts about GenAI taking over the HN front page?

12•blenderob•2d ago•17 comments

Ask HN: Thoughts on the current state of tech meetups in the SF Bay Area?

4•Austin_Conlon•15h ago•1 comments

A disk-first C++ vector engine

4•saeedq•1d ago•0 comments

Train 1T parameter LLM with 8 GPUs?

3•kendy1992•2d ago•1 comments

Do not use Cloudflare DNS regsitrar

10•talkingtab•1d ago•1 comments

Ask HN: Why not have an EU browser?

6•osigurdson•2d ago•20 comments

Sqlit – A lazygit-style TUI for SQL databases

20•MaxTeabag•4d ago•5 comments

Ask HN: What was the best decision you made in your career?

10•chistev•17h ago•10 comments

Ask HN: How do you model temporarily invalid data structures

5•escot•3d ago•1 comments

Did the Linux memory management maintainer "just quit"?

17•hliyan•4d ago•3 comments

You've reached the end!