Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Another npm worm

StepSecurity is reporting the emergence of a new worm affecting npm packages. The design of the worm is nothing new, but the rapidity with which it is exploiting captured npm packager credentials is noteworthy. TL;DR: A self-propagating worm, which we are calling ChainDrop, is spreading rapidly through the npm ecosystem. So far 435 packages and more than 1,550 compromised versions have been…

We haven't written up this one. LWN has the full story — the link below goes straight to it.

Read the original at lwn.net →

More in Tech

What It Really Takes to Get YouTube Live and TikTok Publishing Approved

Building a social media integration is one thing. Getting the social network to actually approve it for production is another.

  • VidSyndicate achieved approvals for YouTube Live and TikTok draft/inbox publishing workflows.
  • YouTube integration required OAuth system, Data API, and live streaming functionality.
  • TikTok branding issues necessitated icon and application identity revisions.