Hacker Newsnew | past | comments | ask | show | jobs | submit | kunalsin9h's commentslogin

As similar to 1st wave of Shai Hulud, this also got it through opentionalDependency. intresting


wow!, but i feel in your github, --for is unnecessary, as in your website the claudes example is the perfect example how --for is not required!


bro, you solved my claude resume session id storage issue, now i an just store them in this, and fetch them with natural language. f!


yes, that was my primary motivator.


it is guaranteed to have everything, i.e no loss in data?


We recently identified a sophisticated supply chain attack vector in the npm ecosystem. The package "express-cookie-parser" impersonates the popular "cookie-parser" but with a critical difference: unlike most malicious packages that trigger during installation, this one maintains perfect API compatibility and only executes its payload when loaded by the application at runtime.

Key findings:

- Uses a domain generation algorithm (DGA) with SHA256 hash to create C2 domains - Self-deletes and removes references from the original index.js - Downloads a "startup.js" payload to Google Chrome's user data directory - Executes using the Node executable in path

This represents a concerning evolution in supply chain attacks, as it avoids detection during installation and security scanning. The npm team acted quickly to remove the package once reported.

We're also working on dynamic analysis tools for open source packages to better detect these types of sophisticated threats. Happy to answer any questions about our methodology or findings!


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: