Javascript

3 posts

/vm2-sandbox-escape/featured-image.png
vm2 Node.js Sandbox Escape 12 Critical Vulnerabilities Two Without a Patch

May 7, 2026

Twelve critical vulnerabilities were just published for vm2, a Node.js security library that sits inside millions of applications. Three of them score a perfect …

/axios-npm-supply-chain-attack/featured-image.png
Axios npm Supply Chain Attack: How a Fake Meeting Compromised 100 Million Downloads

April 4, 2026

Axios, the JavaScript library with over 100 million weekly downloads, was compromised on March 31st. For roughly three hours, every fresh install of those two …

/linux-inside-pdf/featured-image.png
Linux Inside a PDF

January 26, 2026

Linux running inside a PDF. An actual working operating system with a terminal where you can type commands. Open a PDF in Chrome. Wait 30 seconds. You now have …