version 2.3.8 of the #NPM package "cline" installed #OpenClaw on 4000 developers’ machines over 8 hours, because its package.json added a new postinstall command; this was achieved via prompt injection via a GitHub issue title, which was obeyed by Cline’s “AI-powered issue triage workflow”. #security #AI
but #npm has a --before flag you can use for a #cooldown for #security.
on 02025-11-26"safe-npm" is an #npm installer that imposes a 90-day “#cooldown” on installing NPM packages for #security.
on 02025-11-26Russ Cox recommends a different approach to #package-manager #version-control for #NPM
on 02022-01-11the #supply-chain #security #backdoor to steal #bitcoin was in the #npm #JS package flatmap-stream
on 02021-12-14