Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
feross
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
181.
▲
by
feross
1y ago
Correct!
182.
▲
Tier 1 Reachability: Precision CVE Triage for Enterprise Teams
(socket.dev)
3 points
by
feross
1y ago
|
0 comments
183.
▲
by
feross
1y ago
Disclosure: I’m the founder of https://socket.dev A week waiting period would not be enough. On average, npm malware lingers on the registry for 209 days before it's finally reported and removed. Source: https://
184.
▲
by
feross
1y ago
Disclosure: I’m the founder of https://socket.dev npm stats lag. We observed installs while the malicious versions were live for hours before removal. Affected releases we saw: duckdb@1.3.3, @duckdb/duckdb-wasm@1.29.2, @duc
185.
▲
by
feross
1y ago
Disclosure: I’m the founder of https://socket.dev Strongly agree on artifact signing, but it has to be real end-to-end. If the attacker can trigger your CI to sign with a hot key, you still lose. What helps: 1) require offline o
186.
▲
by
feross
1y ago
It was a relay. The fake site forwarded actions to the real npm, so the legit 2FA challenge was triggered by npm and the victim entered the code into the phishing page. The attacker captured it and completed the session, then added an API t
187.
▲
by
feross
1y ago
Disclosure: I’m the founder of https://socket.dev We analyzed this DuckDB incident today. The attacker phished a maintainer on npmjs.help, proxied the real npm, reset 2FA, then immediately created a new API token and published f
188.
▲
by
feross
1y ago
Disclosure: I'm the founder of https://socket.dev . A few concrete datapoints from our analysis of this incident that may help cut through the hand-waving: 1. This is the same campaign that hit Qix yesterday ( https:/&#
189.
▲
DuckDB NPM Account Compromised in Continuing Supply Chain Attack
(socket.dev)
27 points
by
feross
1y ago
|
1 comments
190.
▲
Malicious NPM Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet
(socket.dev)
2 points
by
feross
1y ago
|
0 comments
191.
▲
Rv Is a New Rust-Powered Ruby Version Manager Inspired by Python's Uv
(socket.dev)
3 points
by
feross
1y ago
|
1 comments
192.
▲
Review: Participation in Phase I Clinical Pharmaceutical Research
(astralcodexten.com)
2 points
by
feross
1y ago
|
0 comments
193.
▲
Stop Burning Money on Performance Firefighting
(blog.platformatic.dev)
2 points
by
feross
1y ago
|
0 comments
194.
▲
An Interview with Cloudflare Founder and CEO Matthew Prince About Internet
(stratechery.com)
3 points
by
feross
1y ago
|
0 comments
195.
▲
Links for September 2025
(astralcodexten.com)
1 points
by
feross
1y ago
|
0 comments
196.
▲
Release Notes for Safari Technology Preview 227
(webkit.org)
2 points
by
feross
1y ago
|
1 comments
197.
▲
Nx Investigation Reveals GitHub Actions Workflow Exploit Led to NPM Token Theft
(socket.dev)
4 points
by
feross
1y ago
|
0 comments
198.
▲
Sports Team Owners Like to Win
(bloomberg.com)
2 points
by
feross
1y ago
|
1 comments
199.
▲
Watt 3
(blog.platformatic.dev)
1 points
by
feross
1y ago
|
0 comments
200.
▲
Next-Generation Flamegraph Visualization for Node.js
(blog.platformatic.dev)
17 points
by
feross
1y ago
|
0 comments
201.
▲
Made by Google 2025, AI Trade-Offs, Google and the Long-Term
(stratechery.com)
1 points
by
feross
1y ago
|
0 comments
202.
▲
Massimo
(blog.platformatic.dev)
1 points
by
feross
1y ago
|
0 comments
203.
▲
Wallet-Draining NPM Package Impersonates Nodemailer to Hijack Crypto
(socket.dev)
3 points
by
feross
1y ago
|
0 comments
204.
▲
Benedict Evans: Why AI Isn't What You Think
(fs.blog)
2 points
by
feross
1y ago
|
1 comments
205.
▲
The Economics of Envy
(astralcodexten.com)
5 points
by
feross
1y ago
|
0 comments
206.
▲
VS Code Dev Days – Join an event near you to learn about AI-assisted development
(code.visualstudio.com)
2 points
by
feross
1y ago
|
0 comments
207.
▲
Nx NPM Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools
(socket.dev)
3 points
by
feross
1y ago
|
1 comments
208.
▲
Biotech Dividend Arrived Early
(bloomberg.com)
1 points
by
feross
1y ago
|
1 comments
209.
▲
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials Via
(socket.dev)
3 points
by
feross
1y ago
|
0 comments
210.
▲
John Bragg: The Unknown Billionaire Who Controls Half The
(fs.blog)
5 points
by
feross
1y ago
|
2 comments
More ›