Sponsor of the Day:
Jerkmate
https://securelist.com/shai-hulud-2-0/118214/
Nothing to steal? Let’s wipe. We’re analyzing the Shai Hulud 2.0 npm worm | Securelist
Dec 4, 2025 - Kaspersky researchers uncover new version of Shai Hulud nom worm, which attacks targets in Russia, India, Brazil, China and other countries, and has wiper...
shai hulud 20 npmnothingstealwipe
https://safedep.io/shai-hulud-second-coming-supply-chain-attack/
Shai-Hulud 2.0 npm Supply Chain Attack Technical Analysis - Real-time Open Source Software Supply...
Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware. Technical analysis reveals...
shai hulud 2npm supply chainanalysis real timeopen source software
https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/
The Shai-Hulud 2.0 npm worm: analysis, and what you need to know | Datadog Security Labs
Learn more about the Shai-Hulud 2.0 npm worm.
shai hulud 2datadog security labs0 npmwormanalysis
https://blog.npmjs.org/post/173012543745/v5100.html
npm Blog Archive: v5.10.0
npm Blog (Archive); updates from the npm team are now published on the GitHub Blog and the GitHub Changelog
npm blog archivev5 10
https://expressjs.com/2025/03/31/v5-1-latest-release.html
Express@5.1.0: Now the Default on npm with LTS Timeline
Express 5.1.0 is now the default on npm, and we're introducing an official LTS schedule for the v4 and v5 release lines.
5 1 0expressdefaultnpmlts
https://www.mycyberuniverse.com/how-fix-npm-warn-gulp-babel-requires-peer-babel-core
How to fix: npm WARN gulp-babel@8.0.0 requires a peer of @babel/core@
Apr 7, 2020 - Recently, when attempting to install the gulp-babel package using the npm CLI (“Node package manager”, “Com…
8 0fixnpmwarngulp
https://libraries.io/npm/typescript
typescript 6.0.3 on npm - Libraries.io - security & maintenance data for open source software
TypeScript is a language for application scale JavaScript development - 6.0.3 - a TypeScript package on npm
typescript 6 0npm libraries iosecurity maintenance dataopen source software3
https://libraries.io/npm/byo-skill
byo-skill 0.2.0 on npm - Libraries.io - security & maintenance data for open source software
Agent Skill (agentskills.io spec) teaching Cursor / Claude Code / Codex / Copilot / Goose / any SKILL.md-aware AI how to integrate BYO (bring-your-own-keys) ...
npm libraries iosecurity maintenance dataopen source software0 2byo