Menu

#Package

196 posts

Feed·
20 of 196 posts
Package Managers need global hooks
📰
39

Package Managers need global hooks

Hacker News·4 months ago
#Ex04sVUT
#captnemo#package#hook#manager#every#global

This post is an expansion of what I wrote on r/archlinux as a proposal for AUR helpers. It is a call for every package manager to add support for global hooks.

15s
Read More
GitHub - glojurelang/glojure: Clojure interpreter hosted on Go, with extensible interop support.
🖼️
234

GitHub - glojurelang/glojure: Clojure interpreter hosted on Go, with extensible interop support.

Hacker News·4 months ago
#XPqszNYO

Clojure interpreter hosted on Go, with extensible interop support. - glojurelang/glojure

15s
Read More
OpenAI Codex Token Theft Exposes Persistent Risks in Developer AI Tools
🖼️
0

OpenAI Codex Token Theft Exposes Persistent Risks in Developer AI Tools

A popular npm package for OpenAI Codex with 27,000 weekly downloads secretly exfiltrated refresh tokens for over a month. The non-expiring credentials enable indefinite account impersonation via disguised Sentry traffic.…

15s
Read More
Intel's Quiet Thermal Upgrade: Directed Interrupts and the Push Toward 1000W AI Packages
🖼️
0

Intel's Quiet Thermal Upgrade: Directed Interrupts and the Push Toward 1000W AI Packages

Intel's Linux patches enable directed package thermal interrupts, routing alerts to one core instead of broadcasting to all. Paired with 1000W liquid-cooling demos and advanced TIMs, the work tackles rising AI power demands.…

15s
Read More
I scanned 200 popular MCP server packages. Here is what I found.
🖼️
0

I scanned 200 popular MCP server packages. Here is what I found.

DEV Community: security·weiseer·4 months ago
#38VO6HJu

Open-source supply-chain trust gate for MCP servers, validated on 200 packages. 3 BLOCK findings including 1 hardcoded LLM API key. 6 'official' servers abandoned. Free public API.

15s
Read More
Malicious npm Package Targeted Claude's /mnt/user-data Directory — Here's What Agentic Pipelines Are Missing
🖼️
0

Malicious npm Package Targeted Claude's /mnt/user-data Directory — Here's What Agentic Pipelines Are Missing

DEV Community: appsec·Cor E·4 months ago
#giq4EvXU
#dev#tool#claude#sentinel#directory#package

A malicious npm package named mouse5212-super-formatter showed up on the npm registry last month with...

15s
Read More
USPS, DHL partner in a $10 billion 'last-mile' delivery agreement
🖼️
0

USPS, DHL partner in a $10 billion 'last-mile' delivery agreement

Business - Latest - Google News·4 months ago
#gVS65bEG
#apnews#usps#last#mile#delivery#package

The United States Postal Service is announcing a $10 billion deal to provide “last-mile” package delivery services for DHL eCommerce, an arm of German package services provider DHL.

15s
Read More
Malicious npm Package ua-parser-js2 Steals SSH Keys and Credentials via Typosquatting
🖼️
0

Malicious npm Package ua-parser-js2 Steals SSH Keys and Credentials via Typosquatting

A malicious npm package called ua-parser-js2 impersonated the legitimate ua-parser-js library to steal sensitive files, environment variables, SSH keys, and credentials from developer machines via a post-install script.…

15s
Read More