Sudhanshu2310 1 karma 318d on HN HN profile →
Coverage
We've seen 3 of ~4 submissions
Full eval: 0 Lite-only: 0 Unevaluated: 3
3 stories
1. Someone published a trojan inside a clone of react-refresh
We just found and reported a malicious npm package impersonating react-refresh - 42 million weekly d...
1 points by Sudhanshu2310 7 days ago | 0 comments | skipped
2. The software supply chain has a new problem: AI agents (safedep.io)
4 points by Sudhanshu2310 8 days ago | 0 comments | skipped
3. Malicious NPM package pino-SDK-v2 exfiltrates .env secrets to Discord
We just analyzed a fresh supply chain attack on npm that&#x27;s pretty well-executed.<p>Package: pin...
1 points by Sudhanshu2310 18 days ago | 0 comments | skipped