Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@calimegai.bsky.socialOct 10, 2026, 9:10 AM

Huit paquets malveillants #npm, téléchargés 40 767 fois, diffusent un RAT Overlord et des voleurs d’infos. Campagne MALFEX attribuée à un acteur isolé depuis août 2023. ⚠️🔐 #cybersécurité #malware

thehackernews.com/2026/10/eigh...

@threadlinqs.bsky.socialOct 10, 2026, 6:41 AM

Shai-Hulud's npm worm persists via .claude + VS Code configs, with a token-revoke dead-man's switch. https://intel.threadlinqs.com/threat/TL-2026-3216 #ThreatIntel #ShaiHulud #Mini #npm

Sonatype Q3 2026 Open Source Malware Index: Compounding Supply-Chain Compromise (Mini Shai-Hulud npm wave, mlflow-ui PyPI AI-agent-uploaded malware)
@stackflag.bsky.socialOct 10, 2026, 1:00 AM

CVE-2026-108261 - tinacms
The TinaCMS admin interface builds the preview frame URL from the page’s hash without confirming it points to the same site. An attacker can craft a link that makes the admin load an…

Too many irrelevant or confusing CVEs? Use stackflag.com

#tinacms #npm #CVE #infosec

@valuechainrisk.orgOct 9, 2026, 4:04 PM

Abandoned is a range, not a number. Our Q3 report measures it. Free: valuechainrisk.org/q3 #opensource #npm

Meme. "Nobody:" / "The npm package your bank depends on:" / "Last commit: 2019. Maintainer bio: Moved to a farm. Goats are better than JavaScript." A cartoon goat says "npm? baa." Caption: Abandoned is a range, not a number. Our Q3 report measures it.
@checkmarxzero.bsky.socialOct 9, 2026, 2:56 PM

🚨 6 new CVEs were published yesterday affecting different versions of fast-jwt.

Severity ranges from Medium to Critical, across different vulnerability classes including algorithm confusion and token expiration issues.

👉️ Upgrade to fast-jwt 6.3.4 to be covered against all six.

#AppSec #npm

@stackflag.bsky.socialOct 9, 2026, 7:20 AM

CVE-2019-19919 - handlebars.js
Old versions of Handlebars, a template engine used in web development, can be exploited by hackers to execute malicious code on a server. This can happen if an attacker sends…

Too many irrelevant or confusing CVEs? Use stackflag.com

#handlebarsjs #npm #CVE #infosec

@stackflag.bsky.socialOct 9, 2026, 7:10 AM

CVE-2026-105851 - payload
Versions of the Payload headless CMS before 3.90.0 (and certain canary builds) let users duplicate a document and unintentionally copy data from fields that should be…

Too many irrelevant or confusing CVEs? Use stackflag.com

#payload #elliotpayload #npm #CVE #infosec

@netsecio.bsky.socialOct 9, 2026, 2:06 AM

The 'tensorlake' NPM package was compromised with a self-propagating worm, Shai-Hulud. Version 0.5.144 steals developer credentials (AWS, K8s, SSH keys) and spreads to other packages. C2 uses an Ethereum contract. #SupplyChain #NPM #malware

🌐 cyber[.]netsecops[.]io

@pkgradar.bsky.socialOct 9, 2026, 12:09 AM

⏱ Caught early: npm @xayz/[email protected] was on our radar 53 days before MAL-2026-17384 went public.

#flaggedfirst #npm #malware #supplychainsecurity

@lazarusholic.bsky.socialOct 8, 2026, 11:24 PM

"Evolution of Web3 in Cloud Supply Chain Attacks" published by PaloaltoNetworks. #NPM, #AlluringPisces, #EtherHiding, #PolinRider, #NullReceiver https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks

@stackflag.bsky.socialOct 8, 2026, 10:50 PM

CVE-2026-107722 - fast-jwt
The fast-jwt library (versions 6.2.0 and later) still fails to strip certain non‑space characters before checking a public key format. As a result, an attacker who can add a…

Too many irrelevant or confusing CVEs? Use stackflag.com

#fastjwt #nearform #npm #CVE #infosec

@velocifyer.mastodon.social.ap.brid.gyOct 8, 2026, 7:43 PM

How to self host a web font from Google Fonts, the easy way, via NPM.

https://blog.velocifyer.com/Posts/8,How%20to%20self-host%20a%20font%20from%20Google%20Fonts,%20the%20easy%20way,%20via%20NPM/

#webdev #fonts #webfonts #selfhosting #selfhost #privacy #web #html #css #npm #blog

@hacks.grOct 8, 2026, 4:13 PM

ChainDrop infected 400+ npm packages, according to researchers.

Using Ethereum as a changeable address book let attackers redirect stolen da…

https://en.hacks.gr/ereynites-entopisan-epithesi-poy-chrisimopoiei-to-ethereum-gia-na-allazei-ton-proorismo-klemmenon-stoicheion/

#ChainDrop #Ethereum #npm

Ερευνητές εντόπισαν επίθεση που χρησιμοποιεί το Ethereum για να αλλάζει τον προορισμό κλεμμένων στοιχείων
@momenulahmad.bsky.socialOct 8, 2026, 2:09 PM

SEOSiri Universal Developer UI Kit (@seosiri/developer-ui-kit)
www.npmjs.com/package/@seo...
#typescript #developers #seosiri @seosiri.com #npm

@threadlinqs.bsky.socialOct 8, 2026, 1:10 PM

Fake NebulaAI npm SDKs quietly install a Windows RAT that spies on your camera and mic. https://intel.threadlinqs.com/threat/TL-2026-3049 #ThreatIntel #KNTRAT #NebulaAI #npm

NEBULA: Seven Fake AI SDK Packages on npm Install a Windows RAT (Modified KNTRAT) That Needs No DLL
@stackflag.bsky.socialOct 8, 2026, 11:00 AM

CVE-2026-1774 - ability
The @casl/ability library used in your applications can be tricked into granting actions it shouldn’t. This could let a malicious user perform operations they are not supposed to.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#ability #casl #npm #CVE #infosec

@reconbee.bsky.socialOct 8, 2026, 9:57 AM

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm reconbee.com/tensorlake-n...

#tensorlake #npmpackage #npm #shaihulud #credential #cybersecurity #cyberattack

@thedailytechfeed.comOct 8, 2026, 9:03 AM

New npm malware MALFEX hides Overlord RAT and movinlike inside PNG-files targeting Windows devs. #SecurityNews #npm #MALFEX #SupplyChain #Malware #Windows https://thedailytechfeed.com/malfex-malware-npm-attack-hides-windows-threats-inside-png-files/

@hacks.grOct 8, 2026, 8:29 AM

Checkmarx found eight malicious developer packages with 40,767 downloads—but that number says nothing about how many Windows PCs were infected.

The malware can steal saved p…

https://en.hacks.gr/i-checkmarx-entopise-okto-paketa-poy-mporoyn-na-molynoyn-ypologistes-me-windows/

#MALFEX #Windows #npm

Η Checkmarx εντόπισε οκτώ πακέτα που μπορούν να μολύνουν υπολογιστές με Windows
@sempf.infosec.exchange.ap.brid.gyOct 8, 2026, 3:52 AM

Speaking of patch management, when the hell is someone gonna fix npm? FFS.

https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html

#npm #malware

Load more