T
traeai
Sign in

产品

NPM

别名:npmjs

一个用于管理 JavaScript 包的工具。

相关材料

已收录 10 条与 NPM 相关的内容,按评分排序。

Postmortem: TanStack npm supply-chain compromise

Postmortem: TanStack npm supply-chain compromise

Hacker News Best2746 字 (约 11 分钟)
95

TanStack suffered an npm supply-chain compromise on May 11, 2026, where attackers published 84 malicious versions across 42 packages using GitHub Actions cache poisoning and OIDC token extraction without stealing npm tokens directly.

入选理由:Attackers exploited pull_request_target and GitHub Actions cache poisoning to publish 84 malicious versions in 6 minutes.

FeaturedArticle#Security#Supply Chain#npm#GitHub Actions#TanStack英文
TanStack NPM Packages Compromised

TanStack NPM Packages Compromised

Hacker News Best2056 字 (约 9 分钟)
95

Several latest versions of TanStack's npm packages were found to contain malware, likely due to stolen developer credentials; users are advised to audit dependencies and revoke tokens immediately.

入选理由:受感染的包包括 @tanstack/react-router 和其他子项目,发布时间集中在 2026 年 5 月 11 日。

FeaturedArticle#npm#security vulnerability#TanStack#supply chain attack#frontend英文
TanStack 又被攻击了
https://t.co/aoilMQON1y
感觉现在这安全事件就没停过,Next 前几天也经常被搞。

攻击者发布了 84 malicious versions,
具...

TanStack Is Attacked Again

Viking(@vikingmute)501 字 (约 3 分钟)
87

Attackers used a fake PR to inject malicious code, pollute pnpm cache, and auto-publish 84 compromised npm versions within minutes, affecting 42 packages.

入选理由:攻击者利用伪造的 zblgg 用户提交 PR 7378,成功绕过审查

FeaturedTweet#npm#supply-chain attack#GitHub Actions#TanStack#security中文
别让模型烧Token了!GitHub 20k星神作:把全网变成命令行

OpenCLI is an open-source project on GitHub that structures web pages and chat records through the command line, completing operations without model inference.

入选理由:OpenCLI 可以将微信、Telegram 等私域聊天记录转化为可搜索、可导出的个人信息流。

FeaturedArticle#OpenCLI#Command Line Tool#Data Scraping#AI Agent#Open Source Project中文
A single PR just hijacked the NPM registry...

A single PR just hijacked the NPM registry...

Fireship1632 字 (约 7 分钟)
85

A single PR attacked the NPM registry, compromising over 100 packages with more than 5 million weekly downloads.

入选理由:100+包被污染,每周下载量超500万

FeaturedVideo#NPM#Security#Supply Chain Attack英文
TrapDoor供应链攻击:AI助手成新型攻击面

TrapDoor Supply Chain Attack: AI Assistants Become New Attack Surface

AI HOT 精选184 字 (约 1 分钟)
80

The TrapDoor supply chain attack uses AI assistant configuration files as an attack vector, stealing developer credentials via malicious packages and PR injection.

入选理由:34个恶意软件包针对加密、AI和安全开发者,目标为窃取钱包、SSH密钥和云凭证

FeaturedArticle#Supply Chain Attack#AI Security#npm#PyPI#Crates.io英文
Get started using Three.js without having to use npm

Get started using Three.js without having to use npm

freeCodeCamp.org101 字 (约 1 分钟)
75

This article introduces how to use the Three.js library without using npm, suitable for developers who have basic knowledge of HTML and JavaScript but are not familiar with npm.

入选理由:通过在 HTML 文件中引入 Three.js 的 CDN 链接,可以无需 NPM 直接使用该库。

FeaturedVideo#Three.js#HTML#JavaScript#npm#beginner guide英文
TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages

TanStack disclosed a sophisticated npm supply chain attack that compromised 42 packages, with attackers injecting malicious code by hijacking maintainer accounts and exploiting npm publishing process vulnerabilities—a major security incident targeting the JavaScript ecosystem in 2026.

入选理由:攻击者入侵了42个npm软件包,通过劫持维护者账户注入恶意代码

FeaturedArticle#npm#Supply Chain Security#Cybersecurity#TanStack#Malware英文
针对最近的各种攻击,我一直在用 pnpm 的
minimumReleaseAge=10080 (分钟) 或者 npm 的
min-release-age=7 (天,v11.10+)或者 bun 的
m...

Viking recommends using the package version cooling mechanism provided by pnpm, npm, or bun to defend against npm supply chain attacks, ensuring that newly released packages must cool down for a certain period before being installed, thus avoiding attack windows.

入选理由:pnpm、npm 和 bun 提供了包版本冷却机制,分别设置为 10080 分钟、7 天和 604800 秒。

FeaturedTweet#npm#supply chain attack#security#package manager中文
SuperTechFans 图标

2026 05 20 HackerNews

SuperTechFans11787 字 (约 48 分钟)
42

This article is merely a aggregation of Hacker News top stories with no deep analysis, technical insights, or original commentary; it repackages news and social media posts with low information density and no engineering value.

入选理由:Karpathy 加入 Anthropic,计划扩展 AutoResearch 为递归训练,但社区质疑其创新性。

FeaturedArticle#LLM#Anthropic#OpenAI#npm#security中文

跨材料问答 · NPM

回答基于:NPM 相关 10 条材料
    0 / 500

    AI may generate inaccurate information. Please verify important content.