digitalcourage.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Diese Instanz wird betrieben von Digitalcourage e.V. für die Allgemeinheit. Damit wir das nachhaltig tun können, erheben wir einen jährlichen Vorausbeitrag von 1€/Monat per SEPA-Lastschrifteinzug.

Server stats:

823
active users

#npm

9 posts9 participants0 posts today

Uncovering a Web3 Interview Scam

A Ukrainian Web3 team's interview process involved cloning a GitHub repository containing malicious components. Analysis revealed the project replaced a legitimate dependency with a malicious NPM package, rtk-logger@1.11.5. This package collected sensitive data, including cryptocurrency wallet information, from popular browsers and uploaded it to an attacker-controlled server. The malware also implemented keylogging, screen capture, and clipboard monitoring. Two other GitHub accounts were found using a similar malicious package. The scam aimed to trick interviewees into executing malicious code, potentially leading to data leaks and asset theft. Developers are advised to exercise caution when handling unknown GitHub projects and to use isolated environments for execution.

Pulse ID: 689c7d9c70e5cba54257d1a9
Pulse Link: otx.alienvault.com/pulse/689c7
Pulse Author: AlienVault
Created: 2025-08-13 11:57:16

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

In light of the ongoing enshittification of #GitHub and the inevitable expansion to #npm, I'm delighted to see that although founded by the commercial entity behind #Deno, jsr.io/ shifted to an open governance model earlier this year and is working on "establish[ing] a legal home for JSR, either by joining an existing foundation (e.g., Linux Foundation, OpenJS) or forming its own 501(c)(3) or similar entity."

deno.com/blog/jsr-open-governa

JSRJSR: the JavaScript RegistryJSR is the open-source package registry for modern JavaScript. JSR natively supports TypeScript, and works with all JS runtimes and package managers.

Three facts about Microsoft:

Microsoft recently had it's A.I. division take over Github.

Microsoft also owns npm.

Microsoft also hosts over 11 thousand terabytes of Israeli military data on it's Azure servers collected from the mass surveillance of Palestinians, which the Israeli military uses to blackmail people, hold them in captivity, and justify killing them after the fact.

Leute... ich kack sooo ab. Seit 7 Stunden versuche ich vom Nginx Proxy Manager #NPM (dem Web UI) zum normalen #Nginx zu wechseln, da ich für einige Dinge mehr Einstellungsfreiheiten haben möchte.

Seit 7 Stunden...

Erst gabs riesen Probleme mit den Permissions und den SSL Zertifikaten, dann hat Nginx angefangen rumzuspinnen und Subdomains falsche SSL Zertifikate zugwiesen - weiß Gott warum.

Und als Krönung habe ich es nicht mehr geschafft Mastodon live zu bringen. Ich bin wieder da... und meine Nerven sind blank.

Manchmal frage ich mich eigentlich warum ich mir das antue. Einerseits gibt mir das unfassbare Glücksgefühle, wenn endlich etwas läuft und andererseits zieht mich das so runter, wenn es mal nicht läuft.

Addendum: #siyuan is buggy as fuckery out of the box. My attempts to build the knowledge base constantly ruined.

To be fair, the Moloch thinks it's due to the #NPM (NginX proxy manager) timeouts and store permissions.

But, we will persevere for now.