Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Xipe Totec

Xipe Totec's Journal
Xipe Totec's Journal
November 26, 2025

Widespread Supply Chain Compromise Impacting npm Ecosystem

Source: Cyber Security & Infrastructure Security Agency

Release DateSeptember 23, 2025

CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world’s largest JavaScript registry, npmjs.com. A self-replicating worm—publicly known as “Shai-Hulud”—has compromised over 500 packages.

After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive credentials. The cyber actor then targeted GitHub Personal Access Tokens (PATs) and application programming interface (API) keys for cloud services, including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.[ii]

The malware then:

Exfiltrated the harvested credentials to an endpoint controlled by the actor.
Uploaded the credentials to a public repository named Shai-Hulud via the GitHub/user/repos API.
Leveraged an automated process to rapidly spread by authenticating to the npm registry as the compromised developer, injecting code into other packages, and publishing compromised versions to the registry.[iii]

Read more: https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem



If this is the wrong forum I apologize but getting the message out quickly is important.

November 26, 2025

Madredeus o sonho



Teresa Salgueiro always triggers my limerence.

November 25, 2025

SCI AM - Psychedelics and Immortality Take Center Stage at MAHA Summit

https://www.scientificamerican.com/article/maha-summit-features-talk-of-psychedelics-and-immortality/

November 24, 2025

Psychedelics and Immortality Take Center Stage at MAHA Summit

Social-media influencers and anti-ageing entrepreneurs mingled with top US government officials, including the head of the US National Institutes of Health (NIH), at an exclusive event steps from the White House this month. The meeting’s purpose was to discuss the future of health in the United States.

Organizers called it the MAHA Summit, referring to US health secretary Robert F. Kennedy Jr’s signature ‘Make America Healthy Again’ movement. Attendees included Kennedy, US vice-president JD Vance, NIH director Jayanta Bhattacharya, US Food and Drug Administration chief Marty Makary and the food activist Vani Hari, who blogs under the name Food Babe. Sessions at the summit, which Nature attended, covered a wide range of health-related topics, including psychedelics, brain implants and anti-ageing therapies. Academic researchers and clinicians were not among the speakers at the sessions, which were peppered by comments critical of the medical establishment.

Because science.
November 19, 2025

Why Weirdos Rise To Power



Have you noticed that people in power tend to be a little bit… weird? In today’s video, we take a look at why. Is it the power that makes the weird, or is it the weird that makes them powerful? And how can you use the same principles to get what you want in life? Today we find out.
November 17, 2025

Why I hate the Czech Easter tradition



"Czech Easter: the tradition that horrifies foreigners who hear about it for the first time. Over here we call it "pomlázka, šmigrust, velikonoce". I didn't add any videos of it here, but I'm sure you'll be able to find them with a simple search. This tradition is also practiced in Slovakia and some other countries. Each region has its specifics, but the core of it stays the same: it's degrading and hurtful towards women. Let me tell you a bit more about it in the video as I draw a sketchbook page themed around Czech Easter, paint some eggs, and introduce you to the Easter illustration I drew last year."

- Lucie Ell

I leave it here without comment.
November 3, 2025

This Slime Could Change The World Planet Fix BBC Earth Science



Grown for centuries by indigenous farmers in rural Mexico, this incredibly rare corn can self-fertilise. In episode three of 'Planet Fix', we explore how this wonder crop could help tackle world hunger, and even end farming's toxic reliance on chemical fertilisers for good!
October 29, 2025

If you remember one AI disaster, make it this one



This stuff is chilling. Grab a blankie, pick your favorite teddy, and settle in for one scary story of AI going out of control.

Elon Musk once tweeted: “The safety of any AI system can be measured by its MtH (meantime to H*tler).” This July, it took less than 12 hours for his most advanced AI to become a holocaust-denying Neo-N*zi.

This is the postmortem that never happened, for the most deranged chatbot ever released.
October 28, 2025

Alfonsina y el Mar, Ariel Ramirez (Alfonsina and the Sea)



"Alfonsina y el mar" (lit. 'Alfonsina and the sea') is a zamba composed by Argentine pianist Ariel Ramírez and written by Argentine writer Félix Luna. It was first released as part of Mercedes Sosa's 1969 album Mujeres argentinas. The song is a tribute to Argentine poet Alfonsina Storni, who committed suicide in 1938 by jumping into the sea from a jetty.[1][2] The song is a classic and has been interpreted by many artists of different nationalities.



September 26, 2025

A proper fado can only be sung with eyes wide shut.





You think I'm kidding?

Profile Information

Gender: Do not display
Current location: The Republic of Texas
Member since: Thu Apr 8, 2004, 05:04 PM
Number of posts: 44,457
Latest Discussions»Xipe Totec's Journal