frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Active NPM supply chain attack: Tinycolor and 40 Packages Compromised

https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages
39•feross•1h ago

Comments

JonChesterfield•1h ago
AI detected potential malware. Plus a bunch of words. Is this a real thing? It does look like all the other npm compromise notes. But the page has AI and potential written on it, so the whole thing may be fabricated, and there are no other comments here.

So on balance I guess I'll ignore it. What a time to be a developer.

seanieb•11m ago
socket.dev is a well known a reputable company, and their founder is pretty well known and trusted too. And looking that their blog post it looks like detected a real attack.
kevin_thibedeau•1h ago
To avoid LeftPad 3.0 they're going to have to add some sort of signed capabilities manifest to restrict API access for these narrow domain packages. Then attackers would limited to targeting those with network privileges.
aussieguy1234•59m ago
They're scanning for credentials. If they can get things like AWS credentials, I would expect to see cloud crypto mining as their next move. So it would be a good idea to keep an eye on your infra if you are affected.
efortis•55m ago
Mitigate it with:

  echo "ignore-scripts=true" >> ~/.npmrc

https://blog.uxtly.com/getting-rid-of-npm-scripts
jimmyl02•6m ago
this being the 2nd large compromise of the week is not boding well from the NPM ecosystem...

supply chain is and has been the new gold mine for bad actors it seems

seanieb•36s ago
There have been practical suggestions that could prevent this but NPM has not yet adopted:

- Prevent publishing new package versions for 24–48 hours after account credentials are changed.

- Require support for security keys.

DHH – As I Remember London

https://world.hey.com/dhh/as-i-remember-london-e7d38e64
1•gpi•3m ago•0 comments

Build a Simple VM in Go

https://blog.phakorn.com/posts/2025/building-a-simple-vm/
2•phakornkiong•4m ago•0 comments

How to create a miniature mind inside a chunk of silicon using code

https://python2llms.org/
2•yegortk•5m ago•0 comments

How to Choose and Use Stir Bars: An Authoritative Guide for Lab Managers

https://blog.jmscience.com/how-to-choose-and-use-stir-bars-an-authoritative-guide-for-lab-managers/
1•rolph•12m ago•0 comments

Debugging Equity

https://column.com/blog/debugging-equity/
1•Plasmoid•13m ago•0 comments

Stir Bars Can't Be Ignored

https://www.science.org/content/blog-post/stir-bars-can-t-be-ignored
2•rolph•13m ago•0 comments

Popular npm package compromised in a sophisticated attack affecting 40+ packages

https://twitter.com/feross/status/1967733290565267561
1•claviska•15m ago•1 comments

The Trauma You Need to Learn

https://staysaasy.com/management/2025/09/14/educational-trauma.html
1•thisismytest•16m ago•0 comments

How should 'mirror life' research be restricted? Debate heats up

https://www.nature.com/articles/d41586-025-02902-2
1•Bender•16m ago•1 comments

Recovering LUKS keys from running system

https://jfr.im/blog/2025/03/recovering-luks-keys/
1•melvyn2•16m ago•0 comments

Installing NetWare NFS Gateway 1.2 on NetWare 3.12

https://www.zx.net.nz/netware/server/312-kvm-1/nfsgwy.shtml
1•TMWNN•18m ago•0 comments

Sheriff Warns Doing TikTok 'Door Kick Challenge' in Wyoming Can Get You Killed

https://cowboystatedaily.com/2025/09/15/wyoming-sheriff-warns-against-doing-the-tiktok-door-kick-...
3•Bender•22m ago•1 comments

Show HN: Bulk install nerd fonts in a single command

https://github.com/yusuke99/bulk-nerd-fonts
1•yusuke99•23m ago•0 comments

Show HN: HN Term – browse HN using the terminal

https://github.com/aotakeda/hn-term
2•arthurtakeda•26m ago•0 comments

FBI investigates social media accounts appearing have prior knowledge shooting

https://thepostmillennial.com/fbi-investigates-social-media-accounts-appearing-to-have-knowledge-...
1•Bender•26m ago•0 comments

We Are Not Low Creatures

https://www.theintrinsicperspective.com/p/we-are-not-low-creatures
1•honoredb•27m ago•0 comments

Hugging Face Releases FinePDFs: A 3T-Token Dataset Built from PDFs

https://www.infoq.com/news/2025/09/finepdfs/
1•maxloh•27m ago•0 comments

Show HN: A tool to make a bootable USB installer out of macOS, or download it

https://macdaddy.io/install-disk-creator/
1•feelix•27m ago•0 comments

Norway's 8.5k ft underground pipeline first to store CO2 directly from factories

https://evidencenetwork.ca/norway-is-set-to-strike-it-rich-with-this-pipeline-8500-feet-undergrou...
1•bookofjoe•31m ago•0 comments

Linux for Nintendo 64 (1997)

https://web.archive.org/web/19990220141243/http://www.heise.de/ix/artikel/E/1997/04/036/
4•flykespice•34m ago•0 comments

Marathon experiment offers most precise measurement of nucleon structure yet

https://phys.org/news/2025-08-marathon-precise-nucleon.html
1•PaulHoule•35m ago•0 comments

Aura – Detecting Fake Cell Towers with RF Fingerprinting AI

2•sadpig70•37m ago•0 comments

What's caused reading scores to drop to worst point in decades?

https://www.pbs.org/newshour/show/whats-caused-reading-scores-to-drop-to-worst-point-in-decades-e...
2•geox•38m ago•0 comments

How to Install the Official Atlassian MCP Server for Claude Code

https://blog.johnys.io/how-to-install-the-official-atlassian-mcp-server-for-claude-code-bitbucket...
3•johnys•39m ago•0 comments

Linux phones are more important now than ever

https://feddit.org/post/18353777
18•wicket•42m ago•1 comments

Windows 11 on a 2005 Sun Ultra Opteron PC [video]

https://www.youtube.com/watch?v=LuyC0y7Ahfg
4•sys_64738•44m ago•0 comments

A Closer Look Inside a Robot's Typewriter-Inspired Mouth

https://hackaday.com/2025/09/15/a-closer-look-inside-a-robots-typewriter-inspired-mouth/
1•warrenm•49m ago•0 comments

The awe keeps dropping

https://morrick.me/archives/10137
27•mgrayson•54m ago•13 comments

The Sagrada Família Takes Its Final Shape

https://www.newyorker.com/magazine/2025/09/22/is-the-sagrada-familia-a-masterpiece-or-kitsch
2•pseudolus•54m ago•1 comments

TCG Automate – Scan and Identify Your Trading Cards and List to eBay in Seconds

https://www.tcgautomate.com
1•asassine•56m ago•0 comments