frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

OreNPMGuard v2.0.0 – OSS for Shai-Hulud 2.0 NPM supply chain attack

1•ahsansmir•31m ago
Shai-Hulud 2.0 emerged in November 2025, compromising 738 npm packages and affecting 25,000+ repositories. This is an evolution of the September 2025 attack with new attack vectors:

- Uses `preinstall` hooks (executes earlier than `postinstall`) - Creates malicious GitHub workflows with self-hosted runners - Attempts Docker privilege escalation - Targets multi-cloud credentials

OreNPMGuard v2.0.0 detects both the original and 2.0 variants, scanning for: - 1,291 unique compromised package@version combinations - Malicious hooks, payload files, GitHub workflows - Docker privilege escalation patterns - All known IoCs

Available in Python and Node.js, with GitHub Actions integration.

GitHub: https://github.com/rapticore/OreNPMGuard Threat research: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack

If you've installed any affected packages, rotate your credentials immediately.

Hollywood's dark era: where did all the colour from movies go?

https://www.theguardian.com/film/2025/nov/24/hollywood-dark-era-colour-in-movies-wicked
2•devonnull•42s ago•0 comments

Xleak – terminal Excel viewer with an interactive TUI

https://github.com/bgreenwell/xleak
1•oori•44s ago•0 comments

Those who fly too close to the SUN (Microsystems) eventually get burned

1•dfasoro•1m ago•0 comments

Show HN: I built an O(N) AI using an Agent Swarm. Asking for audit

https://github.com/makimilan/pulse-field-corev
1•makimilan22•2m ago•1 comments

The Bitter Lesson of LLM Extensions

https://www.sawyerhood.com/blog/llm-extension
1•sawyerjhood•5m ago•0 comments

Lower LDL cholesterol linked to higher type 2 diabetes risk indep. of statin use

https://medicalxpress.com/news/2025-11-ldl-cholesterol-linked-higher-diabetes.html
1•bikenaga•6m ago•0 comments

TSMC Arizona Outage Saw Fab Halt, Apple Wafers Scrapped

https://www.culpium.com/p/tsmc-arizona-outage-saw-fab-halt
1•speckx•6m ago•0 comments

Valve coder confirms the Steam Machine will be priced like a PC

https://www.pcgamer.com/hardware/valve-coder-confirms-the-steam-machine-will-be-priced-like-a-pc-...
1•pjmlp•8m ago•0 comments

Powerset's natural language search system (2012)

http://brenocon.com/blog/2012/10/powersets-natural-language-search-system/
1•todsacerdoti•9m ago•0 comments

Blue Origin to Build a "Super Heavy" Rocket to Compete with Starship

https://www.universetoday.com/articles/blue-origin-to-build-a-super-heavy-rocket-to-compete-with-...
2•rbanffy•10m ago•1 comments

Mind-reading devices can now predict preconscious thoughts: is it time to worry?

https://www.nature.com/articles/d41586-025-03714-0
3•srameshc•11m ago•0 comments

Installing Java in 2025, and Version Managers

https://blog.hakanserce.com/post/version_managers/
1•hakanserce•11m ago•0 comments

Companies are crafting new ways to grow cocoa and chocolate alternatives (2024)

https://apnews.com/article/chocolate-cacao-lab-alternatives-climate-change-73904f71a086044fa55b0e...
2•PaulHoule•12m ago•1 comments

What's Like to Be an AI/ML Engineer

https://newsletter.eng-leadership.com/p/whats-really-like-to-be-an-aiml-engineer
2•rbanffy•13m ago•0 comments

Run Local Speech-to-Text Transcription

https://simonlermen.substack.com/p/run-local-speech-to-text-transcription
1•DalasNoin•13m ago•0 comments

Protecting Data-in-Use in the Cloud: A Pragmatic Philosophy

https://www.mimirsec.com/2025/11/24/elementor-855/
1•jboutwell•14m ago•0 comments

Enumerating Three Billion Accounts on WhatsApp [pdf]

https://github.com/sbaresearch/whatsapp-census/blob/main/Hey_there_You_are_using_WhatsApp.pdf
1•fkarg•14m ago•1 comments

Building CallSpark (browser based VoIP): what I learned and what caused pain

1•ahmaliic•14m ago•0 comments

Kennedy sharpens vaccine attacks, without scientific backing

https://www.cbsnews.com/news/rfk-jr-vaccine-safety-aluminum-ingredients/
2•rolph•16m ago•0 comments

Show HN: Prismle – From Query to Candidates in One Human Sentence

https://prismle.com/
1•b1tsoup•16m ago•0 comments

Nancy Pelosi posted up a staggering 16,930% return, beat the market by 581%

https://finance.yahoo.com/news/nancy-pelosi-beat-market-581-162100416.html
5•belter•17m ago•0 comments

Whole-body Learning in Creating Mathematical/Architectural Structures [pdf]

https://archive.bridgesmathart.org/2017/bridges2017-523.pdf
1•surprisetalk•18m ago•0 comments

Vikings. Vikings Everywhere

https://signoregalilei.com/2025/11/13/vikings-vikings-everywhere/
1•surprisetalk•18m ago•0 comments

"Eye" evolving from the Bronze Age to today [video]

https://m.youtube.com/shorts/rWxWj6FTHvk
1•surprisetalk•18m ago•0 comments

Lower cooling costs with deployment of quantum computers in the stratosphere

https://discovery.kaust.edu.sa/en/article/26198/green-quantum-computing-takes-to-the-skies/
1•giuliomagnifico•19m ago•0 comments

Americans are holding onto devices longer than ever and it's costing the economy

https://www.cnbc.com/2025/11/23/how-device-hoarding-by-americans-is-costing-economy.html
4•randycupertino•19m ago•13 comments

Micropackages and Open Source Trust Scaling (2016)

https://lucumr.pocoo.org/2016/3/24/open-source-trust-scaling/
1•coloneltcb•21m ago•0 comments

We deleted our Dockerfiles: a better, faster way to build container images

https://www.rwx.com/blog/we-deleted-our-dockerfiles
6•fourteenminutes•22m ago•1 comments

Gemini 3 beaks OpenAI's long-standing lead in SRE tasks

https://rootly.com/blog/gemini-3-lead-in-sre-tasks
1•sylvainkalache•22m ago•0 comments

First New Malaria Drug in Years Performs Strongly in Late-Stage Testing

https://www.wsj.com/health/pharma/first-new-malaria-drug-in-years-performs-strongly-in-late-stage...
2•geox•23m ago•0 comments