Urgent.News

What's breaking now, across thousands of outlets.

Tech

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in Tech

How to Preserve Key Insertion Order in JavaScript

TL;DR: JavaScript objects do not guarantee insertion order when using integer keys. The ES6 specification forces integer-like keys (array indices) to the front of the object, sorted numerically.

  • JavaScript objects do not guarantee key order with integer keys
  • Use Map or restructure data as array to preserve order
  • Maps guarantee insertion order for all key types

Two Critical Bugs, One Router: What the D-Link DIR-822A Disclosures Mean for Home Networks

Two Critical Bugs, One Router: What the D-Link DIR-822A Disclosures Mean for Home Networks Vulnerability overview Two memory-safety defects were disclosed in the D-Link DIR-822A router on the same…

  • Two critical security flaws discovered in D-Link DIR-822A router
  • CVE-2026-86296 and CVE-2026-86510 are memory safety issues
  • Vulnerabilities could crash device or execute arbitrary code

Cheap Node.js App Logging for Small SaaS — A Signal Quality Experiment

TL;DR: For a small media SaaS comparing an AI experiment across tenant cohorts, the best cheap Node.js logging option is the one that preserves enough context to reproduce a cohort difference without…

  • Three small SaaS options evaluated: Datadog, Better Stack/Logtail, Axiom, Loki
  • Four metrics measured: signal quality, investigation time, ingestion amplification, operator effort
  • Evaluation set of ten cases: tagging failures, retry storms, timeouts, malformed input

More from Wednesday 7 October →