Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
6mile
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
6mile
1y ago
That domain (npmjs[.]help) has been taken down. Looks like it was purchased and started hosting on September 5th, 2025.
32.
▲
by
6mile
2y ago
I wrote this blog article to address several misconceptions I hear when I talk to engineering or infosec teams. The problem of malicious software packages isn't really well understood, so I thought I would try and tackle some misconce
33.
▲
Three myths about NPM Malware
(sourcecodered.com)
1 points
by
6mile
2y ago
|
1 comments
34.
▲
by
6mile
2y ago
Thanks! Lots of tooling out there, but not much uptake. I mean, npm itself has better, more secure alternatives, but is still the most popular registry on the planet. Like, wtf?!
35.
▲
by
6mile
2y ago
Transitive dependencies, yeah, but top-level dependencies that you are installing with npm i or via your manifest file are areas that you do control and can manage.
36.
▲
by
6mile
2y ago
Correct.
37.
▲
Malicious NPM package targets prettier library
(sourcecodered.com)
15 points
by
6mile
2y ago
|
7 comments
38.
▲
by
6mile
2y ago
It's not a smoking gun. It is just one of a number of signals you look for when identifying potentially malicious packages. Other things you look for are number of collaborators, how long it existed, domains it talks to, and artifact
39.
▲
by
6mile
2y ago
Yeah, I agree the incentive structure is broken for bug bounty hunters. Until the BB platforms themselves create some rules for their customers and researchers, we are gonna continue to have the sh*t show that we do now. The reality is tha
40.
▲
by
6mile
2y ago
GitHax is a labour of love right now and is in heavy development. I'm going to create a small beta testing group soon. Hit me up if you want to be in that group. Contact deets are in my GH profile.
41.
▲
NPM packages deploy reverse shells when installed
(sourcecodered.com)
4 points
by
6mile
2y ago
|
0 comments
42.
▲
New Gitloker attack targets GitHub users
(sourcecodered.com)
1 points
by
6mile
2y ago
|
0 comments
43.
▲
by
6mile
3y ago
There has been a lot of noise about software supply chain attacks over the last few years. These threats are often novel, and have colorful names like dependency confusion, repo-jacking, and commit spoofing. Unfortunately, there is no comm
44.
▲
Show HN: Visualize your software supply chain
(github.com)
4 points
by
6mile
3y ago
|
1 comments
45.
▲
Real-time continuous compliance for the SDLC
(securestack.com)
1 points
by
6mile
5y ago
|
0 comments
46.
▲
Show HN: DevSecOps Playbook – step by step guide to building more secure apps
(github.com)
1 points
by
6mile
5y ago
|
0 comments
47.
▲
Show HN: GitHub Action to find Log4j vulnerabilities
(github.com)
2 points
by
6mile
5y ago
|
0 comments
48.
▲
Lessons learned on how to secure Git
(securestack.com)
3 points
by
6mile
5y ago
|
0 comments