Robuta

https://npm-trends.com/ npm-trends – npm trends https://www.npmjs.cn/ npm Docs Documentation for the npm registry, website, and command-line interface npmdocs https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross... remote access trojanaxioscompromisednpmmalicious https://docs.npmjs.com/ npm Docs Documentation for the npm registry, website, and command-line interface npmdocs https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/ The Shai-Hulud 2.0 npm worm: analysis, and what you need to know | Datadog Security Labs Learn more about the Shai-Hulud 2.0 npm worm. https://semgrep.dev/blog/2026/rip-npm-postinstall-scripts-npm-v12-default-change/ RIP npm Postinstall Scripts: npm v12 Kills Auto Script Execution by Default | Semgrep npm v12 finally kills automatic lifecycle script execution by default, the feature behind nearly every major supply chain attack. Here's what's changing, what... https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/ npm install-time security and GAT bypass2fa deprecation - GitHub Changelog Jul 8, 2026 - npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where... npm installtimesecuritygatdeprecation https://npm.chart.dev/@nuxt/ui @nuxt/ui npm downloads - NPM Chart nuxtuinpmdownloadschart https://bundlephobia.com/ Bundlephobia | Size of npm dependencies Bundlephobia helps you find the performance impact of npm packages. Find the size of any javascript package and its effect on your frontend bundle. sizenpmdependencies https://www.jsdelivr.com/package/npm/prismjs prismjs CDN by jsDelivr - A CDN for npm and GitHub A free, fast, and reliable CDN for prismjs. Lightweight, robust, elegant syntax highlighting. A spin-off project from Dabblet. prismjscdnjsdelivrnpmgithub https://securitybridge.com/blog/a-mini-shai-hulud-has-appeared-when-the-npm-supply-chain-reaches-into-sap/ Mini Shai-Hulud: npm Supply Chain reaches into SAP security! Apr 30, 2026 - On April 29, 2026, four official npm packages in the SAP ecosystem were compromised, briefly spreading credential-stealing malware to developer environments. shai huludsupply chainmininpmreaches https://borncity.com/blog/2026/04/24/neue-npm-lieferkettenangriffe-bitwarden-cli-betroffen/ Neue npm Lieferkettenangriffe: Bitwarden/cli betroffenBorns IT- und Windows-Blog Apr 24, 2026 - Es hat die Tage erneut Lieferkettenangriffe von TeamPCP auf npm-Projekte gegeben. Nun wurde auch bekannt, dass der die CLI-Version von Bitwarden betroffen war. neuenpmbitwardencliund https://statically.io/ Statically - A free CDN for Git repositories, npm, and open source projects A free CDN for GitHub, GitLab, Bitbucket, and npm packages. Convert your repository URLs to CDN links instantly. free cdngit repositories https://npm-stat.com/charts.html?package=esprima npm-stat: download statistics for NPM packages download statistics for npm packages download statisticsnpmpackages https://mvnpm.org/ mvnpm - Use NPM packages as Maven/Gradle dependencies Seamlessly integrate NPM packages into Java through Maven and Gradle dependencies. The bridge between NPM and Maven Central. npm packagesusemavengradledependencies https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/ Our plan for a more secure npm supply chain - The GitHub Blog Sep 23, 2025 - GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing. our planmore secure https://npmcongresos.com/ Inicio - NPM Congresos Jun 10, 2026 - Descubre cómo transformamos congresos y eventos corporativos en momentos memorables Somos especialistas en la organización de Congresos, Eventos y... inicionpmcongresos https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/ The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21) May 21, 2026 - Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. threat landscapeattack surfacenpm https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised?ref=andrewshay.me npm debug and chalk packages compromised The popular packages debug and chalk on npm have been compromised with malicious code npmdebugchalkpackagescompromised https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise TeamPCP deploys CanisterWorm on NPM following Trivy compromise Mar 21, 2026 - TeamPCP deploys CanisterWorm on NPM following Trivy compromise teampcpdeploysnpmfollowingtrivy https://npm-stat.com/charts.html?package=nodejs-smtp npm-stat: download statistics for NPM packages download statistics for npm packages download statisticsnpmpackages https://npm-group.fonticket.com/web/login NPM Group Reservation Platform group reservationnpmplatform https://securitybrief.asia/story/claude-code-can-leak-secrets-in-public-npm-packages Claude Code can leak secrets in public npm packages Hundreds of packages could have exposed API keys and logins after Claude Code saved approved commands in a file npm may publish by default. claude codein publicleaksecretsnpm https://pkg-size.dev/ pkg-size | Find the true size of a npm package Find the true size of an npm package find theof apkgsizetrue https://advisories.gitlab.com/pkg/npm/@bunt/app/ Npm/@Bunt/App | GitLab Advisory Database (GLAD) npmbuntappgitlabadvisory https://missrumphiuseffect.blogspot.com/2016/04/npm-celebrations-sky-awareness-week.html?m=0 The Miss Rumphius Effect: NPM Celebrations - Sky Awareness Week The last full week in April (24-30) is Sky Awareness Week . This week provides us all with an opportunity to appreciate the beauty of the ... the miss rumphius effectnpmcelebrationsskyawareness https://advisories.gitlab.com/pkg/npm/devextreme-angular-rpk/ Npm/Devextreme-Angular-Rpk | GitLab Advisory Database (GLAD) npmdevextremeangularrpkgitlab https://advisories.gitlab.com/pkg/npm/@productdevbook/ts-i18n/ Npm/@Productdevbook/Ts-I18n | GitLab Advisory Database (GLAD) npmproductdevbooktsgitlabadvisory https://missrumphiuseffect.blogspot.com/2015/04/npm-project-jumping-into-form-interview_28.html The Miss Rumphius Effect: NPM Project: Jumping Into Form - Interview with Kristine O'Connell George In preparation for sharing forms this month, I wrote to a number of poets and asked if they would respond to a short list of questions on p... the miss rumphius effect https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust?ref=christophermoravec.com Axios supply chain attack chops away at npm trust | Malwarebytes Mar 31, 2026 - Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan supply chain attackaxioschopsawaynpm https://advisories.gitlab.com/pkg/npm/@ensdomains/test-utils/GMS-2025-108/ https://advisories.gitlab.com/npm/@ensdomains/test-utils/GMS-2025-108/ httpsadvisoriesgitlabnpm https://npm.chart.dev/@nuxt/test-utils @nuxt/test-utils npm downloads - NPM Chart Test utilities for Nuxt nuxttestutilsnpmdownloads https://advisories.gitlab.com/pkg/npm/cxt/GMS-2020-218/ https://advisories.gitlab.com/npm/cxt/GMS-2020-218/ httpsadvisoriesgitlabnpmcxt https://advisories.gitlab.com/pkg/npm/@voiceflow/api-sdk/GMS-2025-318/ https://advisories.gitlab.com/npm/@voiceflow/api-sdk/GMS-2025-318/ httpsadvisoriesgitlabnpm https://github.com/kshashikumar/mysql-gui GitHub - kshashikumar/mysql-gui: A Web-based Graphical User Interface NPM package designed to... A Web-based Graphical User Interface NPM package designed to streamline database management and accelerate development workflows for MySQL -... https://eu.connect.panasonic.com/nl/en/smart-factory/npm-gw NPM-GW | Panasonic Connect The NPM-GW SMT mounter combines flexibility, versatility, and precision. npmgwpanasonicconnect https://advisories.gitlab.com/npm/@thangved/callback-window/MAL-2025-47281/ Malicious code in @thangved/callback-window (npm) | GitLab Advisory Database (GLAD) MAL-2025-47281 Malicious code in @thangved/callback-window (npm): This package was compromised by the Shai-Hulud NPM worm. The malicious payload steals tokens... malicious codecallback https://advisories.gitlab.com/pkg/npm/uptime-kuma/CVE-2023-49805/ https://advisories.gitlab.com/npm/uptime-kuma/CVE-2023-49805/ uptime kumahttpsadvisoriesgitlabnpm https://pleasuresfromthepage.blogspot.com/2017/04/npm-day-13-letter-k.html Pleasures from the Page: NPM Day 13: The Letter K My book spine poem for NPM 2017: She walks in beauty A jar of tiny stars Awakening the heart Open the door House of light P... pleasures from the pagenpmdayletterk https://advisories.gitlab.com/npm/@voiceflow/voiceflow-types/GMS-2025-371/ @voiceflow/voiceflow-types contains malware after npm account takeover | GitLab Advisory Database... GMS-2025-371 @voiceflow/voiceflow-types contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was... account takeovervoiceflowtypescontainsmalware https://advisories.gitlab.com/pkg/npm/eslint-config-teselagen/MAL-2025-47313/ https://advisories.gitlab.com/npm/eslint-config-teselagen/MAL-2025-47313/ httpsadvisoriesgitlabnpm https://advisories.gitlab.com/pkg/npm/jsonwebtoken/ Npm/Jsonwebtoken | GitLab Advisory Database (GLAD) npmjsonwebtokengitlabadvisorydatabase https://advisories.gitlab.com/npm/@fishingbooker/react-swiper/GMS-2025-124/ @fishingbooker/react-swiper contains malware after npm account takeover | GitLab Advisory Database... GMS-2025-124 @fishingbooker/react-swiper contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0... https://advisories.gitlab.com/npm/@asyncapi/edavisualiser/GMS-2025-39/ @asyncapi/edavisualiser contains malware after npm account takeover | GitLab Advisory Database... GMS-2025-39 @asyncapi/edavisualiser contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was... account takeoverasyncapicontainsmalware https://documentation.ubuntu.com/rockcraft/latest/common/craft-parts/reference/plugins/npm_use_plugin/ npm Use plugin - Rockcraft documentation The NPM Use plugin packages npm-based projects and, unlike the NPM Plugin, exports artifacts to a shared local directory. Keys: This plugin has no unique keys.... npmusepluginrockcraftdocumentation https://advisories.gitlab.com/pkg/npm/@pendo324/get-process-by-name/ Npm/@Pendo324/Get-Process-by-Name | GitLab Advisory Database (GLAD) by namenpmgetprocessgitlab https://thehackernews.com/2026/01/researchers-uncover-nodecordrat-hidden.html?m=1 Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages researchersuncoverhiddennpmbitcoin https://advisories.gitlab.com/pkg/npm/@voiceflow/husky-config/ Npm/@Voiceflow/Husky-Config | GitLab Advisory Database (GLAD) npmvoiceflowhuskyconfiggitlab https://docs.npmjs.com/cli/v11/using-npm/config/ Config | npm Docs About npm configuration confignpmdocs https://advisories.gitlab.com/pkg/npm/generator-jhipster/CVE-2025-43712/ https://advisories.gitlab.com/npm/generator-jhipster/CVE-2025-43712/ httpsadvisoriesgitlabnpmgenerator https://advisories.gitlab.com/npm/@oku-ui/switch/GMS-2025-202/ @oku-ui/switch contains malware after npm account takeover | GitLab Advisory Database (GLAD) GMS-2025-202 @oku-ui/switch contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was launched.... https://npmtrends.com/ npm trends: Compare NPM package downloads Which NPM package should you use? Compare packages download stats, bundle sizes, github stars and more. Spot trends, pick the winner. npm trendscomparepackagedownloads https://advisories.gitlab.com/pkg/npm/nodebb/CVE-2021-43788/ https://advisories.gitlab.com/npm/nodebb/CVE-2021-43788/ httpsadvisoriesgitlabnpmnodebb https://advisories.gitlab.com/npm/lint-staged-imagemin/GMS-2025-507/ lint-staged-imagemin contains malware after npm account takeover | GitLab Advisory Database (GLAD) GMS-2025-507 lint-staged-imagemin contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was... https://advisories.gitlab.com/pkg/npm/@tanstack/react-query-next-experimental/CVE-2024-24558/ https://advisories.gitlab.com/npm/@tanstack/react-query-next-experimental/CVE-2024-24558/ https://advisories.gitlab.com/pkg/npm/fiora/ Npm/Fiora | GitLab Advisory Database (GLAD) npmfioragitlabadvisorydatabase https://advisories.gitlab.com/npm/@kvytech/components/GMS-2025-140/ @kvytech/components contains malware after npm account takeover | GitLab Advisory Database (GLAD) GMS-2025-140 @kvytech/components contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was... https://github.blog/changelog/2026-03-17-dependabot-now-detects-malware-in-npm-dependencies/ Dependabot now detects malware in npm dependencies - GitHub Changelog Mar 19, 2026 - You can now receive Dependabot alerts when your repositories depend on npm packages with known malicious versions. When you enable malware alerting, Dependabot... dependabotdetectsmalwarenpmdependencies https://advisories.gitlab.com/pkg/npm/degenerator/CVE-2021-23406/ https://advisories.gitlab.com/npm/degenerator/CVE-2021-23406/ httpsadvisoriesgitlabnpmcve https://advisories.gitlab.com/npm/xo-styles/MAL-2025-49071/ Malicious code in xo-styles (npm) | GitLab Advisory Database (GLAD) MAL-2025-49071 Malicious code in xo-styles (npm): This malicious package was published during the PhantomRaven NPM campaign. The malicious payload steals... malicious codexostylesnpmgitlab https://advisories.gitlab.com/npm/@quick-start-soft/quick-document-translator/GMS-2025-256/ @quick-start-soft/quick-document-translator contains malware after npm account takeover | GitLab... GMS-2025-256 @quick-start-soft/quick-document-translator contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called... quick startdocument translator https://advisories.gitlab.com/pkg/npm/@voiceflow/nestjs-mongodb/ Npm/@Voiceflow/Nestjs-Mongodb | GitLab Advisory Database (GLAD) npmvoiceflownestjsmongodbgitlab https://advisories.gitlab.com/pkg/npm/lightning-flow-scanner/ Npm/Lightning-Flow-Scanner | GitLab Advisory Database (GLAD) npmlightningflowscannergitlab https://advisories.gitlab.com/pkg/npm/zapier-async-storage/GMS-2025-682/ https://advisories.gitlab.com/npm/zapier-async-storage/GMS-2025-682/ httpsadvisoriesgitlabnpm https://tracker.debian.org/pkg/node-npm-run-path node-npm-run-path - Debian Package Tracker debian packagenodenpmrunpath https://missrumphiuseffect.blogspot.com/p/npm-2009-poetry-makers.html The Miss Rumphius Effect: NPM 2009 Poetry Makers Here you will find the collected links for my 2009 National Poetry Month Project in which I interviewed poets who write for children (and s... the miss rumphius effectnpmpoetrymakers https://advisories.gitlab.com/pkg/npm/prebid-universal-creative/ Npm/Prebid-Universal-Creative | GitLab Advisory Database (GLAD) npmprebiduniversalcreativegitlab https://thehackernews.com/2022/05/malicious-npm-packages-target-german.html?m=1 Malicious NPM Packages Target German Companies in Supply Chain Attack Researchers uncover a new NPM supply-chain attack campaign in which attackers distribute malicious packages to compromise leading German companies. npm packagesgerman companiesin supplymalicioustarget https://advisories.gitlab.com/pkg/npm/markdown-pdf/CVE-2023-0835/ https://advisories.gitlab.com/npm/markdown-pdf/CVE-2023-0835/ httpsadvisoriesgitlabnpmmarkdown https://advisories.gitlab.com/npm/mon-package-react-typescript/GMS-2025-519/ mon-package-react-typescript contains malware after npm account takeover | GitLab Advisory Database... GMS-2025-519 mon-package-react-typescript contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0... https://advisories.gitlab.com/npm/medusa-plugin-logs/GMS-2025-514/ medusa-plugin-logs contains malware after npm account takeover | GitLab Advisory Database (GLAD) GMS-2025-514 medusa-plugin-logs contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was... https://pleasuresfromthepage.blogspot.com/2018/04/npm-2018-tracy-k-smith-woman-with.html Pleasures from the Page: NPM 2018: Tracy K. Smith - A Woman With a Mission! National Poetry Month 2018 "Give praise with friends near and far, flinging words to the sky!" - Amy Ludwig VanDerwater Today I share... pleasures from the pagetracy k smith https://advisories.gitlab.com/pkg/npm/node-email-check/ Npm/Node-Email-Check | GitLab Advisory Database (GLAD) email checknpmnodegitlabadvisory https://advisories.gitlab.com/pkg/npm/abacus-ext-cmdline/ Npm/Abacus-Ext-Cmdline | GitLab Advisory Database (GLAD) npmabacusextcmdlinegitlab https://web.dev/articles/emscripten-npm?hl=id Emscripten dan npm | Articles | web.dev Bagaimana cara mengintegrasikan WebAssembly ke dalam penyiapan ini? Dalam artikel ini, kita akan mengerjakan ini dengan C/C++ dan Emscripten sebagai contoh. articles webemscriptendannpmdev https://advisories.gitlab.com/pkg/npm/taylored/ Npm/Taylored | GitLab Advisory Database (GLAD) npmtayloredgitlabadvisorydatabase https://eu.connect.panasonic.com/se/sv/smart-factory/npm-gpl NPM-GP/L | Panasonic Connect The fully automated printing solution is part of the "Autonomous Factory" Concept - a factory that immediately responds to every situation and continues to... npmgplpanasonicconnect https://ap.connect.panasonic.com/vn/vi/products/smart-factory/npm-vf NPM-VF | Panasonic Connect Asia The NPM-VF is equipped with a double portal. The SMD and THT components are placed by one placement head per portal. A wide variety of vacuum pipettes and... panasonic connectnpmvfasia https://missrumphiuseffect.blogspot.com/2017/04/npm-2017-day-ten-thanking-my-mother-for.html?m=0 The Miss Rumphius Effect: NPM 2017 Day Ten: Thanking My Mother for Piano Lessons For National Poetry Month this year I am sharing poetry that celebrates my late sister-in-law and what it means to be human. These daily pos... the miss rumphius effect https://advisories.gitlab.com/npm/airbnb-base-typescript-prettier/MAL-2025-48977/ Malicious code in airbnb-base-typescript-prettier (npm) | GitLab Advisory Database (GLAD) MAL-2025-48977 Malicious code in airbnb-base-typescript-prettier (npm): This malicious package was published during the PhantomRaven NPM campaign. The... malicious code https://advisories.gitlab.com/pkg/npm/@asyncapi/parser/ Npm/@Asyncapi/Parser | GitLab Advisory Database (GLAD) npmasyncapiparsergitlabadvisory https://advisories.gitlab.com/pkg/npm/hermes-engine/CVE-2020-1913/ https://advisories.gitlab.com/npm/hermes-engine/CVE-2020-1913/ hermes enginehttpsadvisoriesgitlabnpm https://advisories.gitlab.com/pkg/npm/@airvertco/frappejs/ Npm/@Airvertco/Frappejs | GitLab Advisory Database (GLAD) npmgitlabadvisorydatabaseglad https://advisories.gitlab.com/pkg/npm/quickswap-sdk/GMS-2025-567/ https://advisories.gitlab.com/npm/quickswap-sdk/GMS-2025-567/ httpsadvisoriesgitlabnpmquickswap https://advisories.gitlab.com/pkg/npm/uri-template-lite/ Npm/Uri-Template-Lite | GitLab Advisory Database (GLAD) npmuritemplatelitegitlab https://advisories.gitlab.com/pkg/npm/ngx-ws/MAL-2025-47332/ https://advisories.gitlab.com/npm/ngx-ws/MAL-2025-47332/ httpsadvisoriesgitlabnpmngx https://advisories.gitlab.com/pkg/npm/lite-web-server/ Npm/Lite-Web-Server | GitLab Advisory Database (GLAD) web servernpmlitegitlabadvisory https://advisories.gitlab.com/pkg/npm/snowflake-sdk/CVE-2025-24791/ https://advisories.gitlab.com/npm/snowflake-sdk/CVE-2025-24791/ httpsadvisoriesgitlabnpmsnowflake https://www.techtarget.com/searchitoperations/news/252515031/Pro-Ukraine-sabotage-renews-scrutiny-on-open-source-security NPM 'protestware' raises questions on open source security | TechTarget When a developer deliberately inserted malicious code into an NPM package targeting Russia and Belarus, it crossed a new line in open source security. open source securitynpmraisesquestionstechtarget https://advisories.gitlab.com/pkg/npm/uplot/ Npm/Uplot | GitLab Advisory Database (GLAD) npmgitlabadvisorydatabaseglad https://missrumphiuseffect.blogspot.com/2020/04/npm-2020-natural-bridge.html The Miss Rumphius Effect: NPM 2020 - Natural Bridge Have you ever seen something that takes your breath away? That makes you wonder in awe at the power of the natural world? It doesn't need t... the miss rumphius effectnpmnaturalbridge https://advisories.gitlab.com/npm/@vucod/email/GMS-2025-373/ @vucod/email contains malware after npm account takeover | GitLab Advisory Database (GLAD) GMS-2025-373 @vucod/email contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was launched.... https://pkgtrends.app/ Package Trends: Compare Packagist, PyPI, Hex, npm & WordPress package downloads packagetrendscomparepackagistpypi https://advisories.gitlab.com/npm/@operato/utils/MAL-2025-47263/ Malicious code in @operato/utils (npm) | GitLab Advisory Database (GLAD) MAL-2025-47263 Malicious code in @operato/utils (npm): This package was compromised by the Shai-Hulud NPM worm. The malicious payload steals tokens and... malicious codeutilsnpmgitlabadvisory https://community.atlassian.com/forums/Bitbucket-questions/Not-able-to-publish-npm-package-to-public-nexus-repository/qaq-p/2507521 Solved: Not able to publish npm package to public nexus re... Oct 20, 2023 - Solved: Please find the configured pipeline below tags : '*' : - step : name : Init caches : - node script : - npm config set @apollo247:registry= - npm packagesolvedablepublishpublic https://advisories.gitlab.com/pkg/npm/@asyncapi/specs/GMS-2025-717/ https://advisories.gitlab.com/npm/@asyncapi/specs/GMS-2025-717/ httpsadvisoriesgitlabnpmasyncapi https://advisories.gitlab.com/npm/@browserbasehq/sdk-functions/GMS-2025-53/ @browserbasehq/sdk-functions contains malware after npm account takeover | GitLab Advisory Database... GMS-2025-53 @browserbasehq/sdk-functions contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0... https://advisories.gitlab.com/pkg/npm/loopback/ Npm/Loopback | GitLab Advisory Database (GLAD) npmloopbackgitlabadvisorydatabase https://advisories.gitlab.com/pkg/npm/x402-next/GHSA-3j63-5h8p-gf7c/ https://advisories.gitlab.com/npm/x402-next/GHSA-3j63-5h8p-gf7c/ httpsadvisoriesgitlabnpm https://advisories.gitlab.com/npm/@voiceflow/nestjs-mongodb/GMS-2025-343/ @voiceflow/nestjs-mongodb contains malware after npm account takeover | GitLab Advisory Database... GMS-2025-343 @voiceflow/nestjs-mongodb contains malware after npm account takeover: On November 24th 2025, a new supply chain attack called Shai-Hulud 2.0 was...