
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
nodebb-plugin-slack-integration
Advanced tools
Slack integration plugin for NodeBB with threaded conversations support
A NodeBB plugin that integrates with Slack to send notifications about forum activities using the Slack Bot API.
code, and more preservedchat:write.customize scope)node_modules directorychat:write bot token scope under Bot Token Scopesxoxb-)/invite @YourBotName
xoxb-)#general or #notifications)Toggle which events should trigger Slack notifications:
This plugin uses the official Slack Web API (chat.postMessage) with a Bot Token for posting messages.
chat:write - Post messages to channelschat:write.customize - (Recommended) Customize username and avatar per messagechannels:manage - (Optional) Create channels automatically when they don't existchannels:join - (Optional) Join channels automaticallyaction:topic.post - Triggered when a new topic is createdaction:topic.reply - Triggered when someone replies to a topicaction:user.create - Triggered when a new user registersaction:topic.delete - Cleanup thread timestamps when topic is deletedaction:topic.purge - Cleanup thread timestamps when topic is purgedSettings are stored in the NodeBB database under the key plugin:slack-integration:settings.
chat:write scope (and optionally chat:write.customize)🎉 New Features:
channels:manage and channels:join scopes)Bug Fixes:
🎉 Major Production-Ready Update
Security & Reliability:
Features:
Bug Fixes:
Documentation:
PRODUCTION_IMPROVEMENTS.md - Complete guide to all improvementsFORMATTING_FIXES.md - Text formatting testing guideAVATAR_FIX.md - Avatar display troubleshootingSee PRODUCTION_IMPROVEMENTS.md for detailed technical information.
MIT
FAQs
Slack integration plugin for NodeBB with threaded conversations support
The npm package nodebb-plugin-slack-integration receives a total of 3 weekly downloads. As such, nodebb-plugin-slack-integration popularity was classified as not popular.
We found that nodebb-plugin-slack-integration demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.