Register and share your invite link to earn from video plays and referrals.

Semgrep
@semgrep
Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.
Joined May 2019
205 Following    4.7K Followers
Another npm worm: 1,485 poisoned versions, 379 packages, two intrusion paths. One via stolen tokens, another via compromised source/OIDC trusted publishing. The latter bypasses token rotation. This is the new reality: supply chain attacks exploiting *trusted* mechanisms. We've pushed out rules for Semgrep customers and listed the IoCs for those who aren't, read the blog:
Show more