
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
clouddownloadmanager
Advanced tools
Introducing a feature-rich Telegram bot that enables users to manage downloads with the powerful aria2 downloader. The bot offers a variety of commands to effortlessly control the downloader, such as initiating a download, monitoring download progress, canceling a download, and managing downloaded files.
Run the following command to swiftly install the Cloud Download Manager on your Linux system:
sudo bash -c "$(curl -sL https://unpkg.com/clouddownloadmanager/install.sh)"
Install the Cloud Download Manager package globally with NPMJS:
// Requires NodeJS installed
npm install -g clouddownloadmanager
To start the Cloud Download Manager bot, simply run:
clouddownloadmanager
Alternatively, you can launch the bot with your Telegram bot token:
TELEGRAMBOT=your-bot-token clouddownloadmanager
FAQs
cloud download manager powered by telegram
The npm package clouddownloadmanager receives a total of 0 weekly downloads. As such, clouddownloadmanager popularity was classified as not popular.
We found that clouddownloadmanager demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.