15 place 93 fresh

38 Security Researchers Spot 150,000 Function-less npm Packages in Automated 'Token Farming' Scheme

Slashdot
EditorDavid @ Slashdot 2 place · today 10:34 EDT

Security Researchers Spot 150,000 Function-less npm Packages in Automated 'Token Farming' Scheme

An anonymous reader shared this report from The Register:


Yet another supply chain attack has hit the npm registry in what Amazon describes as "one of the largest package flooding incidents in open source registry history" — but with a twist. Instead of injecting credential-stealing code or ransomware into the packages, this one is a token farming campaign.

Amazon Inspector security researchers, using a new detection rule and AI assistance, originally spotted the suspicious npm packages in late October,

To see detailed statistics for the news please log in »

Read the original

Add your comment
You must be logged in with Facebook to read and write comments.

A newsletter a day!

You may get 10 most important news around midday in daily newsletter. Press the button and we will send you the most important news only, no spam attached.

or register

LIKE us on Facebook so you won't miss the most important news of the day!

News from the same source
Slashdot Slashdot
Gizmodo
Ed Cara @ Gizmodo 1 place · today 06:00 EDT

RFK Jr. Wants to Link Antidepressants Like SSRIs to Mass Shootings. Experts Aren’t Buying It

Studies show that people who commit mass shootings aren't more likely to be taking antidepressants. But is RFK Jr. paying any attention? Read more

975 fresh

🔮
16.11.2025 ♒︎ Dear Aquarius, today awaits a day that can be characterized as a mix of challenges... Read more ›
Eurogamer.net
Vikki Blake @ Eurogamer.net 1 place · today 12:55 EDT

Resident Evil Requiem producer explains why Capcom scrapped multiplayer horror: "We can't just slap on new skins and characters"

The producer of the next highly-anticipated instalment of Resident Evil, Resident Evil Requiem, has teased that the upcoming horror retains "some" elements of its prior life as an online multiplayer open-world game, but wouldn't tell us what, exactly, they are. Read more Read more

938 fresh

Business Insider
Kelly Burch @ Business Insider 1 place · today 12:08 EDT

I'm married to an NFL player. We have 2 homes, and our 3 kids go to different schools to accommodate his schedule.

Clarke Byard is married to Chicago Bear's safety Kevin Byard III. They have two homes, one for during the NFL season, and one in Tennessee. Read more

714 fresh

ScienceDaily
ScienceDaily 1 place · today 12:09 EDT

Researchers combined deep learning with high-resolution physics to create the first Milky Way model that tracks over 100 billion stars individually. Their AI learned how gas behaves after supernovae, removing one of the biggest computational bottlenecks in galactic modeling. The result is a simulation hundreds of times faster than current methods. Read more

544 fresh

Engadget
Cheyenne MacDonald @ Engadget 1 place · today 13:09 EDT

The Meta Quest 3S VR headset drops to a record-low price for Black Friday

Meta's entry-level VR headset, the Quest 3S, is down to an even more budget-friendly price than usual in a deal on Amazon right now. The 128GB Meta Quest 3S is 17 percent off in an early Black Friday deal, bringing it to a record-low price of $250. It normally goes for $300. With the purchase, you also get the game Gorilla Tag for free. There's also a 256GB option, which... Read more

539 fresh

Gizmodo
Justin Carter @ Gizmodo 2 place · today 10:30 EDT

‘Black Panther 3’ is Officially Ryan Coogler’s Next Movie

You asked, and Coogler's finally confirmed it: his next movie to hit the big screen will be another 'Black Panther.' Read more

535 fresh

Gizmodo
Justin Carter @ Gizmodo 3 place · today 12:25 EDT

2026 Begins With a ‘Labyrinth’ Re-Release in Theaters

Before its sequel (probably) comes out, why not watch 'Labyrinth' on the big screen again next January? Read more

503 fresh

Eurogamer.net
Vikki Blake @ Eurogamer.net 2 place · today 09:17 EDT

Sony slaps down fan-made Concord resurrection effort with copyright takedown and "worrying legal action"

Sony has issued a number of DMCA notices against a fan project working to bring Concord back to life. Read more Read more

330 fresh

Business Insider
Callie Ahlgrim @ Business Insider 2 place · today 08:27 EDT

David Harbour is in a PR pickle ahead of 'Stranger Things.' Here's how 2 experts say they'd make the public forget about it.

David Harbour is in a PR crisis after his ex Lily Allen released a breakup album and rumors spread of a clash with "Stranger Things" costar Millie Bobby Brown. Read more

309 fresh

Slashdot
EditorDavid @ Slashdot 1 place · today 12:34 EDT

Could Firefox Be the Browser That Protects the Privacy of AI Users?

Tech entrepreneur/blogger Anil Dash has been critical of AI browsers like ChatGPT Atlas. (He's written that Atlas "substitutes its own AI-generated content for the web, but it looks like it's showing you the web," while its prompt-based/command-line interface resembles a clunky text adventure, and it's true purpose seems to be ingesting more training data.) And at the Mozilla Festival in Spain, "Virtually everyone shared some version of what I'd articulated... Read more

308 fresh

MacRumors
Joe Rossignol @ MacRumors 1 place · today 11:28 EDT

When to Expect the iPhone Air 2 and 20th Anniversary iPhone With Camera Under Screen

Apple plans to release a second-generation iPhone Air and a 20th-anniversary iPhone at separate times in 2027, according to Bloomberg's Mark Gurman. In his Power On newsletter today, Gurman said the next iPhone Air will likely be released around March 2027, alongside the standard iPhone 18 and a lower-end iPhone 18e. The 20th-anniversary iPhone will likely follow in September 2027, with Gurman expecting the device to feature a curved glass... Read more

294 fresh

Eurogamer.net
Vikki Blake @ Eurogamer.net 3 place · today 07:49 EDT

Ubisoft admits AI-generated loading screen "slipped through" into final build of Anno 117: Pax Romana

Ubisoft has told Anno 117: Pax Romana fans that it will be replacing an AI-generated loading screen image, insisting it had "slipped through" and had only meant to be used as a placeholder. Read more Read more

262 fresh

Vox
Avishay Artsy @ Vox 1 place · today 07:15 EDT

Why are there so many billionaires nowadays?

It feels like everyone’s mad at billionaires right now. Maybe it’s the disconnect between Americans struggling with grocery prices and health care premiums and the ultrarich sailing on their super yachts and flying on their private jets. Maybe it’s that Elon Musk is on course to become the world’s first trillionaire. Maybe it’s that billionaires […] Read more

261 fresh

Business Insider
Nathan Rennolds @ Business Insider 3 place · today 06:03 EDT

Glen Powell invited a special guest to his 'SNL' hosting debut: his UPS driver

"He thought it was a scam, but he still came," Powell, 37, said in his opening monologue. Read more

245 fresh

The most popular news from the same source for the last week
Slashdot Slashdot
Slashdot
msmash @ Slashdot · 11/11/2025 15:48 EDT

FFmpeg To Google: Fund Us or Stop Sending Bugs

FFmpeg, the open source multimedia framework that powers video processing in Google Chrome, Firefox, YouTube and other major platforms, has called on Google to either fund the project or stop burdening its volunteer maintainers with security vulnerabilities found by the company's AI tools. The maintainers patched a bug that Google's AI agent discovered in code for decoding a 1995 video game but described the finding as "CVE slop." The confrontation... Read more

1,131

Slashdot
EditorDavid @ Slashdot · 11/09/2025 13:04 EDT

Lost Unix v4 Possibly Recovered on a Forgotten Bell Labs Tape From 1973

"A tape-based piece of unique Unix history may have been lying quietly in storage at the University of Utah for 50+ years," reports The Register. And the software librarian at Silicon Valley's Computer History Museum, Al Kossow of Bitsavers, believes the tape "has a pretty good chance of being recoverable." Long-time Slashdot reader bobdevine says the tape will be analyzed at the Computer History Museum. More from The Register: The... Read more

148

Slashdot
EditorDavid @ Slashdot 3 place · 11/15/2025 10:34 EDT

A 'Peak Oil' Prediction Surprise From the International Energy Agency

"The International Energy Agency's latest outlook signals that oil demand could keep growing through to the middle of the century," reports CNBC, "reflecting a sharp tonal shift from the world's energy watchdog and raising further questions about the future of fossil fuels." In its flagship World Energy Outlook, the Paris-based agency on Wednesday laid out a scenario in which demand for oil climbs to 113 million barrels per day by... Read more

87

Slashdot
msmash @ Slashdot · 11/10/2025 15:51 EDT

The PHP Foundation Is Seeking a New Executive Director

New submitter benramsey writes: The PHP Foundation has launched a search for its next executive director. The Executive Director serves as the operational leader of the PHP Foundation, defining its strategic vision and translating it into reality while managing day-to-day operations and serving as the primary bridge between the Board, staff, community, and sponsors. While the programming language PHP is over 30 years old, the PHP Foundation was only created... Read more

86

Slashdot
BeauHD @ Slashdot · 11/14/2025 18:30 EDT

Russia Imposes 24-Hour Mobile Internet Blackout For Travelers Returning Home

An anonymous reader quotes a report from The Record: Russian telecom operators have begun cutting mobile internet access for 24 hours for citizens returning to the country from abroad, in what officials say is an effort to prevent Ukrainian drones from using domestic SIM cards for navigation. "When a SIM card enters Russia from abroad, the user has to confirm that it's being used by a person -- not installed... Read more

81

Slashdot
BeauHD @ Slashdot · 11/14/2025 19:10 EDT

Five People Plead Quilty To Helping North Koreans Infiltrate US Companies

"Within the past year, stories have been posted on Slashdot about people helping North Koreans get remote IT jobs at U.S. corporations, companies knowingly assisting them, how not to hire a North Korean for a remote IT job, and how a simple question tripped up a North Korean applying for a remote IT job," writes longtime Slashdot reader smooth wombat. "The FBI is even warning companies that North Koreans working... Read more

75

Slashdot
msmash @ Slashdot · 11/12/2025 15:45 EDT

Valve Enters the Console Wars

Valve has unveiled a new Steam Machine console, taking a second shot at living room gaming a decade after its 2015 Steam Machine initiative failed. The 6-inch cube runs Linux-based SteamOS but plays Windows games through Proton, a compatibility layer built on Wine that translates Microsoft graphical APIs. Valve spent over a decade working on SteamOS and ways to run Windows games on Linux after the original Steam Machines failed.... Read more

74

Slashdot
msmash @ Slashdot · 11/12/2025 14:25 EDT

US Ends Penny-Making Run After More Than 230 Years

The US is set to make its final penny. The Philadelphia Mint will strike its last batch of one-cent coins on Thursday, after more than 230 years of production. From a report: The coins will remain in circulation but the phase-out has already prompted businesses to start adjusting prices, as they say pennies are becoming harder to find. The government says the move will save money, or as President Donald... Read more

68

Slashdot
msmash @ Slashdot · 11/14/2025 09:40 EDT

All Lupus Cases May Be Linked To a Common Virus, Study Finds

One of the most common viruses in the world could be the cause of lupus, an autoimmune disease with wide-ranging symptoms, according to a new study. From a report: Until now, lupus was somewhat mysterious: No single root cause of the disease had been found, and while there is no cure, there are medications that can treat it. The research, published in the journal Science Translational Medicine, suggests that Epstein-Barr... Read more

61

Slashdot
BeauHD @ Slashdot · 11/13/2025 08:00 EDT

Iceland Deems Possible Atlantic Current Collapse A Security Risk

Iceland has formally classified the potential collapse of a major Atlantic Ocean current system a national security threat, warning that a disruption could trigger a modern-day ice age in Northern Europe and destabilize global weather systems. The move elevates the risk across government and enables it to strategize for worst-case scenarios. Reuters reports: The Atlantic Meridional Overturning Circulation, or AMOC, current brings warm water from the tropics northward toward the... Read more

61

Most popular sources

  • You see 374 news out of 374.
  • Sources 61 out of 61.
Business Insider 32% 6
Tom's Hardware 17% 7
Gizmodo 16% 10
The Verge 5% 2
Slashdot 5% 2
View sources »

LIKE us on Facebook so you won't miss the most important news of the day!

16.11.2025 13:53
Last update: 13:40 EDT.
News rating updated: 20:40.

What is Times42?

Times42 brings you the most popular news from tech news portals in real-time chart.
Read about us in FAQ section.


Times42 © 2025