
Research
/Security News
Laravel Lang Compromised with RCE Backdoor Across 700+ Versions
Laravel Lang packages were compromised with an RCE backdoor across hundreds of versions, exposing cloud, CI/CD, and developer secrets.
@d-dev/bin-upload-darwin-x64
Advanced tools
Easily distribute binaries via npm, pypi, and GitHub releases.
bin-upload is a CLI tool built with Bun that packages and publishes pre-built binaries to multiple registries and platforms. It supports:
.whl) packages for each platform-specific tag..tar.gz or .zip).# Globally
npm install -g @d-dev/bin-upload
# or as a package dep
npm install -D @d-dev/bin-upload
# or run with npx
npx @d-dev/bin-upload <command>
pip install bin-upload
# or with UV
uv tool install bin-upload
# or run with uvx
uvx bin-upload <command>
Download the appropriate binary for your platform from the releases page.
The following must be installed and available on your path.
bin-upload init
This will walk you through an interactive prompt and generate a bin-upload.config.yaml file.
More on configuration here.
git add .
git commit -m "..."
git tag -a v1.0.0 -m "Release v1.0.0"
bin-upload pack
bin-upload pack -s npm.packageJson.version=1.0.0 -s pypi.metadata.Version=1.0.0
This will generate artifacts in .bin-upload that can be published to npm (tarballs), pypi (wheel), and GitHub (tarballs and zips).
More on the pack command, including how to test artifacts prior to publishing, can be viewed here.
Create a .env file with the following tokens.
# NPM granular access token that bypasses 2FA
# https://docs.npmjs.com/about-access-tokens
NPM_TOKEN="YOUR NPM TOKEN"
# GitHub token with repository metadata read and
# contents write permissions
GITHUB_TOKEN="YOUR GITHUB TOKEN"
PYPI_TOKEN="YOUR PYPI TOKEN"
git push origin main --follow-tags
bin-upload publish
bin-upload publish
This publishes the artifacts generated by the pack command.
More on the publish command, including how to publish with GitHub actions, can be viewed here.
Once published, install from npm or PyPI and confirm:
# npm
npx YOUR_PACKAGE ...
# PyPI
uvx YOUR_PACKAE ...
FAQs
Publish binaries to npm, pypi, and github releases.
The npm package @d-dev/bin-upload-darwin-x64 receives a total of 44 weekly downloads. As such, @d-dev/bin-upload-darwin-x64 popularity was classified as not popular.
We found that @d-dev/bin-upload-darwin-x64 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Laravel Lang packages were compromised with an RCE backdoor across hundreds of versions, exposing cloud, CI/CD, and developer secrets.

Security News
Socket found a malicious postinstall hook across 700+ GitHub repos, including PHP packages on Packagist and Node.js project repositories.

Security News
Vibe coding at scale is reshaping how packages are created, contributed, and selected across the software supply chain