Tag
Node.js
Every Node.js story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 29 · 2026
Read the issue →-
@asyncapi/specs (2.7M weekly downloads) got compromised today via a malicious CI commit
An attacker compromised AsyncAPI repositories to publish malicious npm packages that deploy the Miasma RAT credential stealer. The attack impacts millions of weekly downloads and utilizes advanced obfuscation and multi-channel C2 infrastructure.
Week 28 · 2026
Read the issue →-
Why a five-minute sniff test is your secret supply chain defense
The article advocates for a proactive 'sniff test' methodology to validate the integrity of SBOMs in containerized environments. It highlights how identifying omissions like unpinned packages or missing dependencies is crucial for preventing supply chain attacks.
Week 27 · 2026
Read the issue →-
Phishers Gain Persistence at EU, Asia Hospitality Orgs
Cybersecurity researchers from Microsoft and Trend Micro have uncovered sophisticated phishing campaigns targeting hospitality organizations in Europe and Asia. These attacks leverage malicious archives to deploy persistent malware like Node.js implants and blockchain-based RATs to maintain long-term access.
Week 19 · 2026
Read the issue →-
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
A security scan discovered that 25% of 6,000 web applications fail to verify Stripe webhook signatures, allowing for unauthorized payment bypass. This flaw enables attackers to forge successful payment events and upgrade account statuses without actual charges.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free