cd/entity/npm· home› entities› npm
grep -l @npm /news/*.json | wc -l → 625

npm

mentions 625 type Organization page 29/32 feed RSS

// recent coverage 625 mentions

10:00
2026-06-09
safedep.io
ai-tools

Inside the Miasma Software Supply Chain Attack Toolkit

The Miasma software supply chain attack toolkit has been released as open source across multiple GitHub repositories, likely through compromised developer accounts. The toolkit enables attackers to ex…

00:00
2026-06-07
jackfranklin.co.uk
ai-tools

ai-review: reviewing AI code before it lands

Developer Jack Franklin launched ai-review, an open-source tool that lets terminal-based AI coding agents present plans and diffs in a browser for line-by-line review. The tool bridges the gap between…

17:36
2026-06-06
dev.to
ai-tools

Rust Was Crashing. Go Fixed It. Copilot Showed Me Why

A developer built Delay Mirror, a supply chain security gateway for package managers that blocks downloads of packages published within the last three days, after malicious code was pushed into npm pa…

10:00
2026-06-06
safedep.io
ai-agents

Config Files That Run Code: Supply Chain Security Blindspot

A single unsigned commit to the `icflorescu/mantine-datatable` repository added six files, five of which serve as launchers that execute a 4.3 MB dropper at `.github/setup.js`. The dropper, obfuscated…

10:00
2026-06-05
safedep.io
ai-agents

Miasma Worm Targets AI Coding Agents via GitHub Repos

On June 3, 2026, attackers pushed malicious commits to the GitHub repository `icflorescu/mantine-datatable` and four sibling repos, planting a 4.3 MB payload from the Miasma worm family. The commit ad…

02:23
2026-06-04
techradar.com
ai-tools

OpenAI Codex tool linked to malicious NPM supply chain attack

A malicious npm package posing as a remote web UI tool for OpenAI Codex has been discovered in a supply-chain attack, exfiltrating authentication tokens from developers. The package, "codexui-android,…

09:00
2026-06-01
infoworld.com
ai-safety

AI’s brave new world of technical debt

Mitchell Hashimoto is advising developers to stop updating software dependencies and instead fork and trim libraries, updating only when user-facing issues arise. The recommendation follows a spring o…

← prev page 29 / 32 next →
// co-occurs with top 8 entities
// topics top 6 topics