← All topics

Tag

npm

Every npm story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.

7 items · 6 issues

Week 29 · 2026

Read the issue →

Week 28 · 2026

Read the issue →

Week 27 · 2026

Read the issue →

Week 24 · 2026

Read the issue →

Week 23 · 2026

Read the issue →

Week 20 · 2026

Read the issue →
  • Postmortem: TanStack npm supply-chain compromise

    An attacker successfully compromised 42 TanStack npm packages by chaining GitHub Actions cache poisoning with OIDC token extraction. The breach allowed for the unauthorized publication of malicious versions that could exfiltrate sensitive cloud and infrastructure credentials.

    Cybersecurity Reddit r/netsec Source ↗
  • Official CheckMarx Jenkins package compromised with infostealer

    The TeamPCP hacker group has compromised the Checkmarx Jenkins AST plugin by leveraging credentials stolen from a previous Trivy scanner breach. This supply-chain attack allows for the delivery of credential-stealing malware to developer environments.

    Cybersecurity Reddit r/cybersecurity Source ↗