<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[No new npm packages compromised?]]></title><description><![CDATA[<p>No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?</p>]]></description><link>https://board.circlewithadot.net/topic/0910ebf3-6750-466f-a006-4a7be8ef4d51/no-new-npm-packages-compromised</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 12:38:44 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/0910ebf3-6750-466f-a006-4a7be8ef4d51.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 15 May 2026 17:30:20 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 20:15:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> <span><a href="/user/nuclearoatmeal%40beige.party">@<span>NuclearOatmeal</span></a></span> Yeah if DVWA was installed on thousands of endpoints and *checks notes* also exposed to the Internet <img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f62d.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--sob"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="😭"
      alt="😭"
    /></p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://protean-labs.io/blog/researchers-find-thousands-of-openclaw-instances-exposed">
Protean Labs | Engineering Blog
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://protean-labs.io/blog/researchers-find-thousands-of-openclaw-instances-exposed" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://protean-labs.io/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(protean-labs.io)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://shellsharks.social/users/shellsharks/statuses/116580426371625248</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://shellsharks.social/users/shellsharks/statuses/116580426371625248</guid><dc:creator><![CDATA[shellsharks@shellsharks.social]]></dc:creator><pubDate>Fri, 15 May 2026 20:15:34 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 20:10:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/shellsharks%40shellsharks.social" rel="nofollow noopener">@<span>shellsharks</span></a></span> <span><a href="/user/nuclearoatmeal%40beige.party" rel="nofollow noopener">@<span>NuclearOatmeal</span></a></span> In fairness, isn't OpenClaw basically like a Damn Vulnerable Agent for testing and learning at this point?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580406103561165</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580406103561165</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 20:10:25 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 20:09:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/nuclearoatmeal%40beige.party">@<span>NuclearOatmeal</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> OpenClaw says "my turn" - <a href="https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw" rel="nofollow noopener"><span>https://www.</span><span>cyera.com/blog/claw-chain-cyer</span><span>a-research-unveil-four-chainable-vulnerabilities-in-openclaw</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://shellsharks.social/users/shellsharks/statuses/116580401277620594</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://shellsharks.social/users/shellsharks/statuses/116580401277620594</guid><dc:creator><![CDATA[shellsharks@shellsharks.social]]></dc:creator><pubDate>Fri, 15 May 2026 20:09:11 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 20:07:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/viss%40mastodon.social" rel="nofollow noopener">@<span>Viss</span></a></span> I saw that but no timeline and no descriptions. Could be total bummers like a lot of the "coming soon" stuff from ZDI and Talos. Fingers crossed though.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580394937168070</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580394937168070</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 20:07:35 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 20:04:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> docker 0days coming, stuff embargoed atm. more npm tooooo <a href="https://xchglabs.com/blog/" rel="nofollow noopener"><span>https://</span><span>xchglabs.com/blog/</span><span></span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/Viss/statuses/116580381145600112</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/Viss/statuses/116580381145600112</guid><dc:creator><![CDATA[viss@mastodon.social]]></dc:creator><pubDate>Fri, 15 May 2026 20:04:04 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:55:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/badsamurai%40infosec.exchange">@<span>badsamurai</span></a></span> <span><a href="/user/nuclearoatmeal%40beige.party" rel="nofollow noopener">@<span>NuclearOatmeal</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> zero days. zero days, erryday</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/580/348/048/428/691/original/46a3e87425602202.jpg" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/da_667/statuses/116580349304494700</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/da_667/statuses/116580349304494700</guid><dc:creator><![CDATA[da_667@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 19:55:58 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:55:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> <span><a href="/user/nyanbinary%40infosec.exchange">@<span>nyanbinary</span></a></span> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f910.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--zipper_mouth_face" style="height:23px;width:auto;vertical-align:middle" title="🤐" alt="🤐" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f910.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--zipper_mouth_face" style="height:23px;width:auto;vertical-align:middle" title="🤐" alt="🤐" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f910.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--zipper_mouth_face" style="height:23px;width:auto;vertical-align:middle" title="🤐" alt="🤐" /> pending analysis. Sorry y'all.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/darfplatypus/statuses/116580348380511157</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/darfplatypus/statuses/116580348380511157</guid><dc:creator><![CDATA[darfplatypus@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 19:55:44 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:54:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/nyanbinary%40infosec.exchange">@<span>nyanbinary</span></a></span> That doesn't sound like <span><a href="/user/darfplatypus%40infosec.exchange">@<span>darfplatypus</span></a></span> ... <img class="not-responsive emoji" src="https://media.infosec.exchange/infosec.exchange/custom_emojis/images/000/617/555/original/deb312185359b645.png" title=":brdThink:" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580344782518232</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580344782518232</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 19:54:49 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:47:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> I heard a rumor that it can but it's hard to confirm what with being on fire and all.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/huronbikes/statuses/116580315590096119</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/huronbikes/statuses/116580315590096119</guid><dc:creator><![CDATA[huronbikes@cyberplace.social]]></dc:creator><pubDate>Fri, 15 May 2026 19:47:24 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:47:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> Gearing up for Monday morning...</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/580/309/401/415/820/original/789cc8f4775f0172.jpg" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116093572746253175/statuses/116580315270039470</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116093572746253175/statuses/116580315270039470</guid><dc:creator><![CDATA[jackryder@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 19:47:19 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:43:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> darf asked nicely</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116580299659123681</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116580299659123681</guid><dc:creator><![CDATA[nyanbinary@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 19:43:21 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:41:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/nuclearoatmeal%40beige.party" rel="nofollow noopener">@<span>NuclearOatmeal</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/580/287/471/620/508/original/710b322fcc5357ed.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116580290643143611</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116580290643143611</guid><dc:creator><![CDATA[badsamurai@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 19:41:03 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:36:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/huronbikes%40cyberplace.social" rel="nofollow noopener">@<span>huronbikes</span></a></span> You mean fire can grow?!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580271269194995</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116580271269194995</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 19:36:08 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:29:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> maybe all the fire is hiding some fire we don't know about</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/huronbikes/statuses/116580243405152209</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/huronbikes/statuses/116580243405152209</guid><dc:creator><![CDATA[huronbikes@cyberplace.social]]></dc:creator><pubDate>Fri, 15 May 2026 19:29:02 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 19:24:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> </p><p>Day ain't over yet.</p>]]></description><link>https://board.circlewithadot.net/post/https://beige.party/users/NuclearOatmeal/statuses/116580225206967388</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://beige.party/users/NuclearOatmeal/statuses/116580225206967388</guid><dc:creator><![CDATA[nuclearoatmeal@beige.party]]></dc:creator><pubDate>Fri, 15 May 2026 19:24:25 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 18:46:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> here you go <a href="https://www.openwall.com/lists/oss-security/2026/05/15/2" rel="nofollow noopener"><span>https://www.</span><span>openwall.com/lists/oss-securit</span><span>y/2026/05/15/2</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rikusilvola/statuses/116580076151722517</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rikusilvola/statuses/116580076151722517</guid><dc:creator><![CDATA[rikusilvola@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 18:46:30 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 18:22:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/viss%40mastodon.social">@<span>Viss</span></a></span> <span><a href="/user/ciaranmak%40mastodon.ie">@<span>ciaranmak</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> well runc isn't really a very strong boundary compared to gvisor or kata containers, so I'm not too worried there</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/starchturrets/statuses/116579983649375278</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/starchturrets/statuses/116579983649375278</guid><dc:creator><![CDATA[starchturrets@mastodon.social]]></dc:creator><pubDate>Fri, 15 May 2026 18:22:59 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 18:12:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/ciaranmak%40mastodon.ie">@<span>ciaranmak</span></a></span> <span><a href="/user/starchturrets%40mastodon.social">@<span>starchturrets</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> oh god yes. docker 0day. shoot that shit right into my veins</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/Viss/statuses/116579942643869116</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/Viss/statuses/116579942643869116</guid><dc:creator><![CDATA[viss@mastodon.social]]></dc:creator><pubDate>Fri, 15 May 2026 18:12:33 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 17:59:43 GMT]]></title><description><![CDATA[<p><span><a href="/user/starchturrets%40mastodon.social">@<span>starchturrets</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> I will report back because tbh if I don't end up out in the pub this evening I'm probably gonna test this one out</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.ie/users/ciaranmak/statuses/116579892188969193</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.ie/users/ciaranmak/statuses/116579892188969193</guid><dc:creator><![CDATA[ciaranmak@mastodon.ie]]></dc:creator><pubDate>Fri, 15 May 2026 17:59:43 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 17:55:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/ciaranmak%40mastodon.ie">@<span>ciaranmak</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> I'm not so sure how bad this is in comparison to the embargoed KVM one at <a href="https://xchglabs.com/blog/" rel="nofollow noopener"><span>https://</span><span>xchglabs.com/blog/</span><span></span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/starchturrets/statuses/116579876339728689</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/starchturrets/statuses/116579876339728689</guid><dc:creator><![CDATA[starchturrets@mastodon.social]]></dc:creator><pubDate>Fri, 15 May 2026 17:55:42 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 17:54:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> BleepingComputer are getting slow in their old age (likewise).</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/McCovican/statuses/116579870770409292</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/McCovican/statuses/116579870770409292</guid><dc:creator><![CDATA[mccovican@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 17:54:17 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 17:51:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/mccovican%40infosec.exchange">@<span>McCovican</span></a></span> I think that one was published yesterday, which is like three years ago in this week time.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116579860667874285</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116579860667874285</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 17:51:42 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 17:51:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> <em>Shenanigans ahoy!</em> <a href="https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/" rel="nofollow noopener"><span>https://www.</span><span>bleepingcomputer.com/news/secu</span><span>rity/popular-node-ipc-npm-package-compromised-to-steal-credentials/</span></a> <img class="not-responsive emoji" src="https://media.infosec.exchange/infosec.exchange/custom_emojis/images/000/468/711/original/5e45484de7b362e5.png" title=":neocat_foxmask:" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/McCovican/statuses/116579858016665203</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/McCovican/statuses/116579858016665203</guid><dc:creator><![CDATA[mccovican@infosec.exchange]]></dc:creator><pubDate>Fri, 15 May 2026 17:51:02 GMT</pubDate></item><item><title><![CDATA[Reply to No new npm packages compromised? on Fri, 15 May 2026 17:46:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/starchturrets%40mastodon.social">@<span>starchturrets</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> noice, mom and dads malware sandbox got REKT</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.ie/users/ciaranmak/statuses/116579838413944847</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.ie/users/ciaranmak/statuses/116579838413944847</guid><dc:creator><![CDATA[ciaranmak@mastodon.ie]]></dc:creator><pubDate>Fri, 15 May 2026 17:46:03 GMT</pubDate></item></channel></rss>