Researcher hacks over 35 tech firms by creating public NPM packages

This page summarizes the projects mentioned and recommended in the original post on /r/programming

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • event-stream

    Discontinued EventStream is like functional programming meets IO

  • foo-bar version 1.0 depends on bada-boom 1.0 which depends on bada-bing 1.0. Now you update to foo-bar 1.1 because of some critical update, which in itself now depends on bada-boom 2.0 and bada-bing 2.0. But unbeknownst to you and the author of foo-bar, the bada-boom and bada-bing project was taken over by another maintainer who made an update, but also added some trojan horse code to specifically attack certain users, which was obfuscated and remained undetected. Which has happened before - not just browser extensions are affected by malicious attackers taking over useful projects.

  • project

  • foo = "0.1" git_foo = { git = "https://github.com/example/project", package = "foo" } custom_foo = { version = "0.1", registry = "custom", package = "foo" }

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • steal-ur-stuff

    Steal Ur Stuff

  • Not only that it can run arbitrary code contained in a Gist and I showed this 4 years ago https://github.com/tanepiper/steal-ur-stuff

  • asdf

    Extendable version manager with support for Ruby, Node.js, Elixir, Erlang & more

  • It's a version manager. https://github.com/asdf-vm/asdf

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Kotlin version manager

    2 projects | /r/Kotlin | 7 Dec 2023
  • are people still scripting in 2023? / decision paralysis

    1 project | /r/AskProgramming | 22 Sep 2023
  • Using multiple rails versions on the same computer

    2 projects | /r/rails | 8 Jun 2023
  • [Question] How do you guys separate your tooling for different version

    3 projects | /r/golang | 18 May 2023
  • Install instructions do not work on debian stable.

    1 project | /r/Pleroma | 29 Apr 2023