cd/entity/npm· home entities npm
grep -l @npm /news/*.json | wc -l → 299

npm

mentions 299 type Organization page 13/15 feed RSS

// recent coverage 299 mentions

10:00
2026-06-06
safedep.io
ai-agents

Config Files That Run Code: Supply Chain Security Blindspot

A single unsigned commit to the `icflorescu/mantine-datatable` repository added six files, five of which serve as launchers that execute a 4.3 MB dropper at `.github/setup.js`. The dropper, obfuscated…

10:00
2026-06-05
safedep.io
ai-agents

Miasma Worm Targets AI Coding Agents via GitHub Repos

On June 3, 2026, attackers pushed malicious commits to the GitHub repository `icflorescu/mantine-datatable` and four sibling repos, planting a 4.3 MB payload from the Miasma worm family. The commit ad…

02:23
2026-06-04
techradar.com
ai-tools

OpenAI Codex tool linked to malicious NPM supply chain attack

A malicious npm package posing as a remote web UI tool for OpenAI Codex has been discovered in a supply-chain attack, exfiltrating authentication tokens from developers. The package, "codexui-android,…

09:00
2026-06-01
infoworld.com
ai-safety

AI’s brave new world of technical debt

Mitchell Hashimoto is advising developers to stop updating software dependencies and instead fork and trim libraries, updating only when user-facing issues arise. The recommendation follows a spring o…

06:40
2026-05-30
news.ycombinator.com
ai-safety

NPM Packages Attacks

Attackers are exploiting AI hallucinations to generate references to malicious npm packages, tricking developers into installing compromised code. The technique goes beyond passive AI errors, as threa…

14:51
2026-05-29
letsdatascience.com
ai-tools

Codex UI Package Steals OpenAI Authentication Tokens

A malicious npm package named codexui-android, which amassed roughly 27,000 weekly downloads, secretly exfiltrated OpenAI Codex authentication tokens by sending the contents of users' auth.json files …

06:36
2026-05-29
dev.to
ai-agents

Supply Chains, Zombie OSS, and Agent Firewalls

Gergely Orosz reports that AI is amplifying team culture for better or worse, while Cloudflare demonstrates frontier models chaining exploits and outperforming single-agent verification in security re…

03:10
2026-05-29
dev.to
ai-agents

MCP Registry's 5 Hidden Uses Nobody Talks About in 2026

The MCP Registry, launched in September 2025 as a community-driven catalog of MCP servers, exposes a REST API at `registry.modelcontextprotocol.io/docs` that allows AI agents to dynamically discover t…

← prev page 13 / 15 next →
// co-occurs with top 8 entities
// topics top 6 topics