cd/entity/npm· home› entities› npm
grep -l @npm /news/*.json | wc -l → 625

npm

mentions 625 type Organization page 28/32 feed RSS

// recent coverage 625 mentions

07:00
2026-06-16
githits.com
ai-agents

Show HN: GitHits Public Beta 0.9

GitHits launched its public beta 0.9, a CLI and local MCP server that gives coding agents access to open-source code behind project dependencies. The tool indexes open-source code and documentation, a…

03:11
2026-06-16
gist.github.com
ai-agents

Humble Pi — local agentic coding on minimal hardware

A developer released Pi, a coding agent that runs entirely on a local machine without API keys or cloud dependencies. Pi works with a local llama.cpp server hosting Google Gemma 4 models, enabling off…

01:09
2026-06-16
byteiota.com
ai-safety

That LinkedIn Job Offer Hid a Backdoor in npm install

A developer received a LinkedIn message from a recruiter at a crypto startup asking to review a GitHub repository before a technical interview. The repository contained a backdoor in npm's prepare scr…

20:54
2026-06-15
news.ycombinator.com
ai-agents

CPanel over MCP

A developer released cPanel MCP, a tool enabling AI agents to administer cPanel servers via WHM and UAPI, on npmjs.com. The tool dynamically probes server versions to avoid documentation drift and has…

20:00
2026-06-15
roman.pt
ai-safety

A backdoor in a LinkedIn job offer

A security researcher received a LinkedIn message from a recruiter at a crypto startup asking them to review a GitHub repo. The repo contained a backdoor that would execute arbitrary code when depende…

16:38
2026-06-14
github.com
ai-tools

Structured Subagents for Claude Code

WastedCode released TrueCast, a CLI and plugin system that installs portable expert personas—such as product manager, architect, and security reviewer—into Claude Code sessions. The tool provides vers…

07:58
2026-06-14
dev.to
artificial-intelligence

Why your AI agent ignores the rules you wrote

A developer explains why AI agents often ignore explicit rules, using a React Native project example where a rule against using 'pnpm add' for native packages was broken, causing a build failure. The …

09:22
2026-06-13
socket.dev
developer-tools

Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformati

Socket's Threat Research team identified 23 new malicious PyPI packages in the Mini Shai-Hulud, Miasma, and Hades supply chain attacks, expanding the campaign to 471 artifacts across npm and PyPI. The…

07:21
2026-06-13
developer.microsoft.com
developer-tools

Agent just scaffolded a project from 2020

An AI agent scaffolded a project using an outdated 2020 version because npx resolved to an old package version without engine constraints, due to npm's version resolution prioritizing engine compatibi…

17:54
2026-06-11
devblogs.microsoft.com
developer-tools

Your agent just scaffolded a project from 2020

AI agents using npx without specifying a version can inadvertently scaffold projects from outdated templates due to npm's engine compatibility resolution, which prioritizes older versions without engi…

14:00
2026-06-09
arize.com
ai-agents

How to detect credential theft in AI agent harness traces

In May 2026, two supply-chain attacks targeted AI coding tools including Claude Code and Cursor, with one malicious VS Code extension stealing npm, AWS, GitHub, and SSH credentials from 6,000 develope…

← prev page 28 / 32 next →
// co-occurs with top 8 entities
// topics top 6 topics