Thx for sharing. From what I understand:
Your repo had a GitHub Action that ran on every PR.
An attacker submitted a malicious PR that modified the Action to steal your npm token.
Was the main cause a GitHub Action misconfiguration?
17.09.2025 02:51 — 👍 1 🔁 0 💬 1 📌 0
Hacking on https://mastrojs.github.io – the simplest web framework and site generator.
Runs on Deno, Node.js, Bun and in your browser as a VSCode extension.
https://github.com/mb21
stoyan.me, PerfPlanet, "JavaScript Patterns", "React: Up & Running", YSlow, SmushIt. Formerly of Facebook, WebPageTest, Yahoo
Working to make computers better. Cofounder of Ink & Switch, Heroku, Muse, Local First Conf.
They/Them. Open source. Comic books. Board games.
Prev: Babel, Yarn, Flow, Parcel, Biome
React core team • Forbes 30 worst over 30
⚛️ Maintaining TanStack Query
🔮 https://query.gg
👨💻 Software Engineer @sentry.io
📚 Blog at https://tkdodo.eu
🇦🇹 Vienna, Austria
👧👦 Father of two
San Francisco, typescript, xmplaylist.com
Doing frontend stuff at @sentry.io
British, in Brooklyn. Software engineer making newsy, phone sized things for the @nytimes.com Interactive News team. Infrequently blog about code stuff at https://alastair.is
Coding @ github.com/qix-, making an operating system @ github.com/oro-os
Building AIs at snowmountain.ai
I love machines, mathematics and music.
Earlier: Meta, Foresight Institute, Clear, Gupshup, IIML, IITKGP
❤️ http://isfixable.com
https://nilesh.trivedi.link/
https://x.com/nileshtrivedi
https://fosstodon.org/@nilesh
Sync Conf is a boutique conference on the future of real-time, collaborative, agentic software development. 12th Nov2025 in SF.
https://syncconf.dev/ | View talks: https://tinyurl.com/mr3yzxea
Instructor @egghead.io
Content Engineer @inngest.com
Associate Professor at @cst.cam.ac.uk, researching decentralised systems and security protocols. Advisor to the Bluesky team. Wrote “Designing Data-Intensive Applications” (O’Reilly). he/him
An independent research lab exploring the future of tools for thought.
We envision a new computer that amplifies human intelligence. A system that helps you think more clearly, collaborate more effectively, and is available anywhere and anytime.
a whimsicott crawled into your compiler and got stuck
call me miguel. yes! i am a furry artist!
⌨️ mcy.gay
🎨 art.mcy.gay
💰 art.mcy.gay/comms
🔞 @art.mcy.gay
📍Seattle, WA
science journalist | good physics, bad physics, and sometimes ugly physics
Signal: dgaristo.72
Email: digaristo@gmail.com
Developer Advocate on the Firebase team @ Google
YouTube: https://www.youtube.com/@PeterFriese
Blog: https://peterfriese.dev
Senior Flutter Dev at Ardley. Mostly post about #flutter & software engineering. She/Her
#flutterista #womenintech
Product Lead at Google working on Firebase serverless products & Genkit framework. Opinions are my own.
🇺🇦 🛫 🗽 🛫 Seattle 🛫 ☀️
South Florida.