
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
To install this package, you can use one of the following commands, depending on your package manager.
npm install crossbuild
pnpm add crossbuild
yarn add crossbuild
This package will automatically install the most common modules that are used, but if you want to pick and choose, you can install the @crossbuild/core package and then only the modules you want.
CrossBuild is a library that allows you to build bots for Discord and Guilded, at the same time. It is designed to be as simple as possible, while still being powerful.
If you want to contribute to CrossBuild, please read the contributing guidelines first. We welcome all types of contributions, from bug fixes to documentation improvements! If you have any questions, feel free to join our Discord server and ask in the #crossbuild channel.
CrossBuild is licensed under the MIT License.
FAQs
A powerful framework to create cross-platform Discord and Guilded bots
We found that crossbuild demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.