Attackers are sending emails from spoofed [email protected] addresses linking to a typosquatted clone site (npnjs.com) to steal credentials. This attack is designed to hijack npm accounts. Careful with those email links: socket.dev/blog/npm-phi... #nodejs #JavaScript
Attackers are sending emails from spoofed [email protected] addresses linking to a typosquatted clone site (npnjs.com) to steal credentials. This attack is designed to hijack npm accounts. Careful with those email links: socket.dev/blog/npm-phi... #nodejs #JavaScript
nodejs.org/en/blog/rele...
nodejs.org/en/blog/rele...
Built by @mainmatter.com
Learn more ➡️ mainmatter.com/blog/2025/03...
🧵1/4
Doesn't have to be fresh, last 5 years is ok.
Respond with ghsa link or package+version - I can look it up myself.
(repost for reach a lot please)
Doesn't have to be fresh, last 5 years is ok.
Respond with ghsa link or package+version - I can look it up myself.
(repost for reach a lot please)
Hitting "Y" adds the current SHA to the URL. This ensures your link doesn't break as the repository changes over time.
Hitting "Y" adds the current SHA to the URL. This ensures your link doesn't break as the repository changes over time.
home-assistant.typeform.com/communitysur...
home-assistant.typeform.com/communitysur...