NPM hack articles were mentioned multiple times on SN over the last year, I'm not a dev, I didn't pick up on this.
(Blockstream and Zeus were included in the affected wallets list but both have stated they don't use NPM and their wallets are unaffected.)
#441476
28th February 2024
#977339
11th May 2025
#613912
19th July 2024
#522259
28th April 2024
#754534
5th November 2024
It seems like AI would be the perfect tool for code package repos like NPM and PyPI to use to scan all new uploaded code and alert on vulnerabilities.
https://socket.dev does this. Great service
There are many reason why I check Stacker News but the Emergency/Urgent news is my top reason.
Stacker new is on it!