<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Dependency Injection</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Dependency Injection feed</description>
    <item>
      <title>NPM Ecosystem Suffers Two AI-Enabled Credential Stealing Supply Chain Attacks</title>
      <link>https://www.infoq.com/news/2025/10/npm-s1ngularity-shai-hulud/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Dependency+Injection</link>
      <description>&lt;img src="https://res.infoq.com/news/2025/10/npm-s1ngularity-shai-hulud/en/headerimage/generatedHeaderImage-1760893318793.jpg"/&gt;&lt;p&gt;The Node Package Manager (npm) ecosystem has suffered from two major supply chain attacks in recent months, affecting hundreds of packages and exposing developers to credential theft and data exfiltration. The attack vector of these incidents shows an AI-enabled evolution of how open-source software dependencies can be compromised.&lt;/p&gt; &lt;i&gt;By Matt Saunders&lt;/i&gt;</description>
      <category>Dependency Injection</category>
      <category>Software Supply Chain</category>
      <category>Application Security</category>
      <category>NPM</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Mon, 20 Oct 2025 10:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2025/10/npm-s1ngularity-shai-hulud/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Dependency+Injection</guid>
      <dc:creator>Matt Saunders</dc:creator>
      <dc:date>2025-10-20T10:00:00Z</dc:date>
      <dc:identifier>/news/2025/10/npm-s1ngularity-shai-hulud/en</dc:identifier>
    </item>
  </channel>
</rss>
