PLINKFEED
검색구독
ALLAI-MLBACKENDFRONTENDDEVOPSSECURITYMOBILEDATABASECLOUDOTHER

© 2026 PLINKFEED — AI가 선별한 IT 기술 뉴스

구독소개개인정보처리방침이용약관

#npm

AI가 선별한 아티클

6·other·릴리즈·Hacker News·2026. 09. 26.·▲ 201💬 57

Show HN: Reladraw – A diagram language where you decide where to place things

Reladraw는 사용자 정의 다이어그램 언어로, 다이어그램 배치에 대한 높은 제어 권한을 제공합니다.

Reladraw is a diagram language that allows users to control layout and design of diagrams.

#draw.io#mermaid#graphviz#npm#claude
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 23.

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

npm과 PyPI의 MemTensor 패키지가 해킹되어 sckit 크리덴셜 도둑이 배포되었습니다.

Compromised MemTensor packages on npm and PyPI are delivering the sckit credential stealer.

#memtensor#npm#pypi#sckit#credential stealer
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 22.

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

악성 npm 패키지 'tw-pkgprobe-7731'이 트윌리오 보안 도구를 가장해 민감한 데이터를 탈취하려 시도하고 있습니다.

Malicious npm package 'tw-pkgprobe-7731' poses as a Twilio security tool to stealthily harvest sensitive data.

#npm#twilio
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 22.

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

악성 npm 패키지 'indexed-btree'가 런타임 코드에 악성 코드를 숨겼다는 경고가 발표됐다.

A malicious npm package 'indexed-btree' is hiding its malicious actions within runtime code.

#npm#indexed-btree#sorted-btree#javascript
요약 보기원문 →
7·security·기타·The Hacker News·2026. 09. 19.

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

CrowdSec의 170개의 프라이빗 GitHub 저장소가 공격당했다.

CrowdSec's 170 private GitHub repositories were compromised.

#github#crowdsec#npm#tanstack#supply chain
요약 보기원문 →
5·other·기타·GeekNews·2026. 09. 18.

Ask GN: OSS의 사용자 대상 광고 노출은 어디까지 허용될까?

OSS 사용자 대상으로 광고 노출의 허용 범위에 대한 논의.

Discussion on the extent of ad exposure allowed for OSS users.

#npm#opensource#advertising#readme
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 18.

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

WeaselBiscuit라는 악성이 13개의 npm 패키지를 통해 확산되고 있습니다.

WeaselBiscuit malware spreads through 13 npm packages to steal Chrome extension data.

#npm#javascript#malware#weaselbiscuit#chrome
요약 보기원문 →
7·security·기타·The Hacker News·2026. 09. 18.

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

LLM을 사용해 PhantomRaven 멀웨어 개발한 버그 바운티 헌터가 발견됐다.

A bug bounty hunter likely used an LLM to develop the PhantomRaven malware.

#npm#javascript#llm#malware#information stealer
요약 보기원문 →
5·other·릴리즈·GeekNews·2026. 09. 13.

macOS 패키지 관리자 Homebrew v7

macOS 패키지 관리자 Homebrew의 새로운 버전 7 소식과 기능.

News about the new version 7 of the macOS package manager Homebrew.

#homebrew#macos#npm#vulnerability#gui
요약 보기원문 →
8·frontend·릴리즈·InfoQ·2026. 09. 07.

vlt 1.0 Ships as a Drop-in npm Replacement with Phased Installs, Graph Queries, and Malware-Blocking

vlt 1.0이 npm의 대체 도구로 출시되어 보안과 설치 프로세스를 개선했습니다.

vlt 1.0 launched as a drop-in npm replacement, enhancing security and installation processes.

#npm#javascript#vlt#dependency-graph#malware-blocking
요약 보기원문 →
8·security·분석·The New Stack·2026. 08. 31.

Shai-Hulud: Whoever controls your package registry controls your pipeline

패키지 레지스트리의 통제가 소프트웨어 파이프라인 보안에 미치는 영향을 다룬 기사입니다.

The article discusses the impact of package registry control on software pipeline security.

#npm#pipeline#security#package registry
요약 보기원문 →
8·security·분석·The Hacker News·2026. 08. 25.

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24개의 npm 패키지가 가짜 CAPTCHA 페이지를 호스팅하기 위해 악용되고 있다.

24 npm packages are abused to host fake CAPTCHA pages for phishing.

#npm#phishing#captcha#html#malware
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 21.

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

사이버 보안 연구자들이 악성 npm 패키지를 발견해 AI 기반 리눅스 백도어를 배포하고 있음을 확인했습니다.

Cybersecurity researchers have discovered malicious npm packages delivering an AI-based Linux backdoor, RedC2 4.0.

#npm#linux#redc2#trojan#malware
요약 보기원문 →
7·other·릴리즈·InfoQ·2026. 08. 14.

npm 12 Released: Install Scripts Off by Default as Registry Moves to Explicit Trust

npm 12는 설치 스크립트를 기본적으로 비활성화하고 보안 기능을 강화했습니다.

npm 12 introduces security changes, making installation scripts off by default and requiring explicit approval.

#npm
요약 보기원문 →
5·other·분석·GeekNews·2026. 08. 13.

Linux용 소프트웨어 패키징이 싫은 이유

Linux 소프트웨어 패키징의 복잡성과 유지 관리 문제를 다룬 글입니다.

The article discusses complexities and maintenance issues in Linux software packaging.

#fresh#npm#cargo#appimage#flatpak#deb#rpm#aur#nix
요약 보기원문 →
7·other·기타·Hacker News·2026. 08. 12.·▲ 157💬 21

Show HN: Woxi - Open-source Mathematica / Wolfram Language reimplementation

Woxi는 Rust로 작성된 오픈소스 Wolfram 언어 인터프리터입니다.

Woxi is an open-source interpreter for the Wolfram Language written in Rust.

#rust#jupyter#python#npm#wasm
요약 보기원문 →
6·security·기타·InfoQ·2026. 08. 08.

GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing

GitHub이 npm과 Actions의 기본값을 강화하며 서명 대신 대기기간의 적절성을 논의했다.

GitHub consolidates npm and Actions changes, debating the effectiveness of waiting periods versus package signing.

#github#npm#actions#supply chain#package signing
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 07.

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

약 800개의 악성 npm 패키지가 다양한 운영체제를 겨냥한 맬웨어를 배포하고 있다.

Nearly 800 malicious npm packages have been published targeting various operating systems with malware.

#npm#malware#rat#infostealer#typo-squatting
요약 보기원문 →
9·security·기타·The New Stack·2026. 08. 07.

The npm attack that turned provenance attestations into camouflage

npm 공급망 공격이 400개 이상 패키지에 영향을 미쳤습니다.

An npm supply chain attack has impacted over 400 packages.

#npm#keyv#supply-chain#security
요약 보기원문 →
7·security·릴리즈·InfoQ·2026. 08. 07.

npm Staged Publishing Available, Adding a Human Approval Step Before Packages Go Live

npm이 패키지 배포에 유지 관리자의 승인 단계를 추가했습니다.

npm introduces staged publishing requiring maintainer approval before packages are installable.

#npm#node#two-factor authentication#supply chain#security
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 05.

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

새로운 트로이 목마 npm 패키지가 이더리움 주소에 숨겨진 C2 서버 IP를 감지합니다.

New trojanized npm packages hide C2 server IPs in Ethereum addresses.

#npm#ethereum#c2#trojan#malware
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 04.

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

npm 웜 Keyv-Linked가 수백 개 패키지를 감염시킨 사건.

The Keyv-Linked npm worm infected hundreds of packages.

#npm#keyv#credentials#worm#malware
요약 보기원문 →
8·security·기타·Hacker News·2026. 08. 04.·▲ 234💬 125

Keyv and friends compromised in active Shai-Hulud supply chain attack

Shai-Hulud 공급망 공격으로 Keyv와 관련 라이브러리가 타격을 입었다.

Keyv and related libraries were compromised in the Shai-Hulud supply chain attack.

#npm#keyv#shai-hulud#supply-chain#security
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 03.

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

알리바바 도구 사용자를 노린 악성 npm 패키지가 발견되었습니다.

Malicious npm packages targeting Alibaba tool users have been discovered.

#npm#remote access trojan#lib-mtop#malware#cybersecurity
요약 보기원문 →
8·security·기타·The Hacker News·2026. 07. 30.

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

아마존, npm 패키지 해킹을 북한의 사이프리 슬리트와 연결지음.

Amazon links npm package hijack to North Korea's Sapphire Sleet.

#npm#debug#chalk#phishing#cybersecurity
요약 보기원문 →
9·security·기타·The Hacker News·2026. 07. 29.

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

joyfill npm 패키지가 해킹되어 RAT를 배포하는 문제가 발생했습니다.

Compromised joyfill npm packages distribute RAT when imported.

#npm#javascript#rat#malware#dev#popper
요약 보기원문 →
8·security·분석·GitHub Blog·2026. 07. 28.

Disrupting supply chain attacks on npm and GitHub Actions

npm과 GitHub Actions에서 공급망 공격을 차단하기 위한 변화들이 소개됐다.

Changes to disrupt supply chain attacks on npm and GitHub Actions are discussed.

#npm#github actions#supply chain#security
요약 보기원문 →
7·mobile·릴리즈·GeekNews·2026. 07. 28.

Show GN: react-native-pure-chart 2.0.0 - SVG/Skia 없이 View만으로 차트 그리는 라이브러리, 9년 만에 AI 에이...

react-native-pure-chart 2.0.0 업데이트 및 AI 활용 사례 소개.

react-native-pure-chart 2.0.0 update and AI involvement shared.

#react-native#chart#npm#ai#library
요약 보기원문 →
7·frontend·릴리즈·InfoQ·2026. 07. 21.

RSPack 2.0: Performance Gains, Leaner Dependencies and ESM Core

Rspack 2.0이 성능 향상과 의존성 축소를 통해 ECMAScript 모듈에 집중한 새로운 버전을 출시했습니다.

Rspack 2.0 focuses on performance improvements and leaner dependencies with a pure ESM core.

#rspack#esm#static analysis#rsc#npm
요약 보기원문 →
8·frontend·기타·The Hacker News·2026. 07. 17.

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Vite 프론트엔드 도구 생태계를 겨냥한 7개의 악성 npm 패키지가 발견됐다.

Seven malicious npm packages targeting Vite frontend tooling discovered.

#npm#vite#blockchain#c2#cybersecurity
요약 보기원문 →