
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@jesscss/parser-shared
Advanced tools
@jesscss/parser-sharedPublished runtime support for the Parseman grammar facts that the CSS, Less, SCSS, and Jess parsers compose. The CSS grammar keeps these modules external so downstream dialect packages can follow their composed pieces across the package boundary; parser consumers receive this package through the parser dependency closure.
The package intentionally has no root entrypoint. Its public surface is limited
to the three grammar-fact modules in exports.
Modules here are consumed by two or more parsers and are parser-specific. Anything used by one parser belongs in that parser. Anything general-purpose belongs elsewhere.
This package builds first. All four parsers depend on it, and building them
against a stale lib/ fails silently and green.
FAQs

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.