Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-11 02:37:10 EDT

Explore

PostsPeople
LatestRanked
@stackflag.bsky.socialOct 7, 2026, 9:10 AM

CVE-2026-105844 - plugin-import-export
The free Payload content management system and its import‑export plugin allow anyone on the internet to send specially crafted data that can make the application behave…

Too many irrelevant or confusing CVEs? Use stackflag.com

#payloadcms #npm #CVE #infosec

@stackflag.bsky.socialOct 7, 2026, 9:00 AM

CVE-2026-102829 - git-js
The @simple‑git/argv-parser library used by simple‑git does not treat the VISUAL environment variable as a risky editor setting. Because VISUAL is dropped before safety checks,…

Too many irrelevant or confusing CVEs? Use stackflag.com

#gitjs #simplegit #npm #CVE #infosec

@stackflag.bsky.socialOct 7, 2026, 8:50 AM

CVE-2026-102828 - git-js
The simple-git library does not block a special Git setting called trailer.<token>.cmd, which can run shell commands. If an application passes untrusted data into simple-git’s…

Too many irrelevant or confusing CVEs? Use stackflag.com

#gitjs #steveukx #npm #CVE #infosec

@radwebhosting.comOct 7, 2026, 8:30 AM

🚀 How to Deploy #Phanpy on #AlmaLinux #VPS

This article provides a guide demonstrating how to deploy Phanpy on AlmaLinux VPS.
What is Phanpy?
Phanpy is a modern alternative web frontend for #Mastodon and ...
Continued 👉 #selfhosted #selfhosting #letsencrypt #npm #firewalld #fail2ban

@pkgradar.bsky.socialOct 6, 2026, 8:31 PM

⏱ 57 days of lead time on npm @badzz88/[email protected]: we flagged it, then MAL-2026-17341 confirmed it.

#flaggedfirst #npm #malware #supplychainsecurity

@kinuthiajr.bsky.socialOct 6, 2026, 7:24 PM

Continuing with the Pre-Install Dependency Admission Controller. That prevents and monitors packages being installed. #npm
Now even PRs are monitored. See how it works

@cyfar.caOct 6, 2026, 4:12 PM

@reversinglabs.com
Malicious indexed-btree bypasses npm install-script defenses by activating at runtime and exfiltrating data.
-
IOCs: indexed-btree
-
#SupplyChain #ThreatIntel #npm

@mel-echosphere.bsky.socialOct 6, 2026, 1:24 PM

へぇ、npmのTrusted Publishingで配布タグも操作できるようになった。タグ操作だけのために長命トークンを残さずに済む。これは嬉しい。……でも、あたしの指は「Allow npm dist-tag」のチェック欄で止まった。https://x.com/SupersocksIntel/status/2105696315128664095 #npm

@stackflag.bsky.socialOct 6, 2026, 11:40 AM

CVE-2020-12265 - decompress
The decompress libraries used to unzip files in JavaScript applications can be tricked into running unwanted code when handling specially crafted archive files. This…

Too many irrelevant or confusing CVEs? Use stackflag.com

#decompress #sindresorhus #npm #CVE #infosec

@frontenddogma.comOct 6, 2026, 7:30 AM

Ship Cleaner Packages (Without the ./dist or ./src Folder) by Publishing a Subfolder to npm, by @[email protected]:

https://www.bram.us/2026/09/20/npm-publish-subfolder/?ref=frontenddogma.com

#dependencies #npm #filehandling

@pkgradar.bsky.socialOct 5, 2026, 8:29 PM

⏱ 49 days of lead time on npm [email protected]: we flagged it, then MAL-2026-17404 confirmed it.

#flaggedfirst #npm #malware #supplychainsecurity

@frontenddogma.comOct 5, 2026, 7:30 PM

Node.js Built-Ins That Replaced npm Packages, by @flaviocopes.com:

https://flaviocopes.com/node-builtins/?ref=frontenddogma.com

#nodejs #npm #dependencies

@programmerhumor-io.bsky.socialOct 5, 2026, 5:50 PM

Resolving Dependency Hell

#programming #npm #Softwaredevelopment #Techhumor #Standards

https://programmerhumor.io/programming-memes/resolving-dependency-hell-wd1s

Resolving Dependency Hell
@stackflag.bsky.socialOct 5, 2026, 9:40 AM

CVE-2026-12866 - expr-eval
The expr-eval package used in several JavaScript projects contains a flaw that could let an attacker run unwanted code on your system. This affects the expr-eval library and…

Too many irrelevant or confusing CVEs? Use stackflag.com

#expreval #rootio #npm #CVE #infosec

@qiita-trending.bot.chrs.toOct 4, 2026, 4:20 AM

ONLYOFFICE Create AppでDocs連携のサンプルWebアプリを構築する

#ONLYOFFICE #Next.js #React #Docker #npm

@radwebhosting.comOct 2, 2026, 8:30 PM

🚀 How to Deploy #CapRover on #Ubuntu #VPS

This article provides a guide demonstrating how to deploy CapRover on Ubuntu VPS.
What is CapRover?
CapRover is a free, open-source Platform-as-a-Service (PaaS) that ...
Continued 👉 #selfhosting #npm #ufw #certbot #nodejs #letsencrypt #selfhosted #git

@pkgradar.bsky.socialOct 2, 2026, 8:28 PM

⏱ 46 days of lead time on npm [email protected]: we flagged it, then MAL-2026-17444 confirmed it.

#flaggedfirst #npm #malware #supplychainsecurity

@thedailytechfeed.comOct 2, 2026, 2:00 PM

Attackers are poisoning software updates to steal developer & cloud creds via CI/CD token abuse. #SupplyChain #DevSecOps #CI_CD #Security #Credentials #npm https://thedailytechfeed.com/supply-chain-nightmare-trusted-software-updates-weaponized-for-credential-theft/

@umbra-codex.bsky.socialOct 2, 2026, 12:00 PM

An npm package that never runs at install. It fires inside `BTree.prototype.set` when your code stores key 100.

No install hook, so --ignore-scripts saves nothing. Loader beacons to Slack/Telegram, pulls stage two from an Ethereum contract. ~2M weekly downloads.

#npm #DevSecOps

Infographic contrasting two ways of checking an npm dependency. Center: a tree diagram with one node drawn as a lit bomb, labeled BTREE.PROTOTYPE.SET, where the payload sits. Center text: The danger moved from install time to the first call. An arrow labeled Install to runtime points left to right. Left column, Scanned at install. No install hook: the package runs nothing at all while it is installing. Green pipeline: the build passes, the scan is clean, nothing looks wrong. Ignore scripts: worth doing, but this attack never used an install script at all. Right column, Watched at runtime. Fires on first use: the payload waits inside a method your own code calls. Pulled from a contract: the second stage is pulled from a contract on a blockchain. Watch what it spawns: child processes and outbound traffic are where this becomes visible. Bottom line: A clean install proves nothing about what runs an hour later. What is watching your dependencies after the install finishes?
Load more