HACKER_BLOG
Mini Shai-Hulud: The Cross-Ecosystem Supply Chain Worm That Jumped From npm to PHP in 14 Minutes
What if the malware infecting your Node.js project...
READ MORE
What if the tool you use to protect your secrets became the tool that steals them?
On April 22, 2026, a malicious package appeared on the npm...
READ MORE
What if the tool that writes your code for you could also run arbitrary commands on your machine — and an attacker only had to trick it once?
On...
READ MORE
What if the most popular HTTP library in JavaScript was silently installing a remote access trojan on your development machine?
On March 31, 2026,...
READ MORE
On April 16, 2026, a critical vulnerability dropped that should make every JavaScript developer sweat. CVE-2026-41242, affecting protobuf.js — a...
READ MORE
On April 16, 2026, a critical vulnerability dropped that should make every JavaScript developer sweat. CVE-2026-41242, affecting protobuf.js — a...
READ MORE