cd/entity/npm· home› entities› npm
grep -l @npm /news/*.json | wc -l → 623

npm

mentions 623 type Organization page 19/32 feed RSS

// recent coverage 623 mentions

14:07
2026-08-12
github.com
developer-tools

anti-slop: Opinionated Oxlint rules

Developer Dillon Mulroy released anti-slop, an open-source (MIT) plugin of opinionated Oxlint rules that reject low-evidence and low-signal TypeScript and JavaScript patterns, distributed via source a…

00:00
2026-08-12
ai2rules.dev
ai-safety

The Switch Inside the Room

A coding-agent security tool shipped by an unnamed developer was found to have three critical flaws, including a kill switch at `.claude/gate-off` that the agent could create without denial, allowing …

00:00
2026-08-12
ai2rules.dev
ai-tools

A Scanner Flagged Our Supply-Chain Package. It Was Right.

Socket, a supply-chain security scanner, flagged the npm package ai2rules-harness with a Supply Chain Security score of 64%, prompting its developer to discover that the package's postinstall script f…

01:56
2026-08-08
opensourcemalware.com
ai-tools

The OpenSourceMalware Show #16

On Tuesday, threat actors compromised Jared Wray's GitHub account to publish a worm based on the open-sourced Mini Shai-Hulud malware, spreading to over 400 packages including Keyv and cacheable, with…

23:26
2026-08-06
opensourcemalware.com
ai-safety

Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

A threat actor published more than 700 malicious packages to the npm registry over 48 hours, using AI-generated typo-squatted names to deliver a cross-platform RAT and infostealer. The packages, such …

14:03
2026-08-06
wiz.io
ai-infrastructure

Cloud Threat Highlights: H1 2026

Wiz's Research and CIRT teams reported a 60% increase in significant cloud security incidents in H1 2026 compared to H2 2025, driven by a doubling of supply-chain attacks and new vulnerability disclos…

11:05
2026-08-04
kuber.studio
ai-products

Claude Code Source Code Analysis

On March 31, 2026, Chaofan Shou discovered that Anthropic's Claude Code source code was exposed via a sourcemap file in the npm package, revealing the entire source code of the AI coding CLI. The leak…

19:41
2026-08-03
github.com
developer-tools

Show HN: Yet Another OpenCode Plugin

A developer released Yet Another OpenCode Plugin, an opencode plugin that adds terse response modes, a YAGNI-based 'lazy dev' ruleset, and two read-only agents (Review and Dream) to the opencode AI co…

09:00
2026-08-03
infoworld.com
ai-safety

Three AI security mistakes that will haunt enterprises

Enterprises are facing three major AI security mistakes as AI agents move from pilots to production, according to an InfoWorld analysis. The mistakes include unvetted dependencies from package registr…

← prev page 19 / 32 next →
// co-occurs with top 8 entities
// topics top 6 topics