Search
For "npm" across CVEs, vendor advisories, threat actors, IOCs, security research, and news.
The Axios npm compromise was visible in registry metadata before anyone ran npm install
submitted by /u/GapLimp8396 [link] [comments]
The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort
arXiv:2605.17062v2 Announce Type: replace Abstract: Spracklen et al. (USENIX Security '25) showed that code-generating large language models hallucinate package names that do not exist on PyPI or npm at rates ranging from 5.2% on commercial