# software packages

Published articles for software packages.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## @mastra npm scope takeover: 143 packages backdoored via compromised contributor account

DevFeed: [@mastra npm scope takeover: 143 packages backdoored via compromised contributor account](<https://devfeed.tech/articles/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account-13149.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account>)

Published: 2026-06-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-takeover](<https://devfeed.tech/tags/npm-takeover.md>), [packages](<https://devfeed.tech/tags/packages.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The article reports that an attacker used a compromised former contributor account to republish all 143 packages in the @mastra npm scope on June 17, 2026. The malicious versions could disable TLS verification, download a cryptocurrency wallet stealer and remote access trojan, and establish command-and-control access. It recommends auditing dependency trees and lockfiles and rotating credentials on affected hosts.

### Source excerpt

A supply chain attack compromised all 143 @mastra packages. Chainguard customers stayed protected through malware blocking and source-built libraries.

## Introducing Chainguard OS Packages: Secure ingredients for custom container builds

DevFeed: [Introducing Chainguard OS Packages: Secure ingredients for custom container builds](<https://devfeed.tech/articles/introducing-chainguard-os-packages-secure-ingredients-for-custom-container-builds-13112.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-os-packages>)

Published: 2026-03-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [chainguard sboms](<https://devfeed.tech/topics/chainguard-sboms.md>), [APK](<https://devfeed.tech/topics/apk.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [automation](<https://devfeed.tech/tags/automation.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-os-packages](<https://devfeed.tech/tags/chainguard-os-packages.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software-packages](<https://devfeed.tech/tags/secure-software-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-packages](<https://devfeed.tech/tags/zero-cve-packages.md>)

### AI overview

Chainguard introduces Chainguard OS Packages, a service providing continuously maintained, enterprise-grade packages and base images for teams that build custom container images. Customers retain control over image composition and build tooling while Chainguard handles package sourcing, rebuilding, vulnerability remediation, and SBOM generation.

### Source excerpt

Chainguard OS Packages are enterprise-grade, zero-CVE packages and base images built and continuously maintained in the Chainguard Factory.

## How to enable Debian 12 Backports repository

DevFeed: [How to enable Debian 12 Backports repository](<https://devfeed.tech/articles/how-to-enable-debian-12-backports-repository-41932.md>)

Original publisher: [Read original article](<https://www.cyberciti.biz/faq/install-enable-debian-linux-12-backports-repository/>)

Author: Vivek Gite

Published: 2024-05-11T11:02:39Z

Content type: tutorial

Language: en

Sources: [nixCraft: Linux Tips, Hacks, Tutorials, And Ideas In Blog Format (RSS/FEED)](<https://devfeed.tech/sources/nixcraft-linux-tips-hacks-tutorials-and-ideas-in-blog-format-rss-feed.md>)

Topics: [Debian](<https://devfeed.tech/topics/debian.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [apt](<https://devfeed.tech/topics/apt.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [apt-cache](<https://devfeed.tech/tags/apt-cache.md>), [debian](<https://devfeed.tech/tags/debian.md>), [debian-linux](<https://devfeed.tech/tags/debian-linux.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [easy](<https://devfeed.tech/tags/easy.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [install](<https://devfeed.tech/tags/install.md>), [linux](<https://devfeed.tech/tags/linux.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [packages](<https://devfeed.tech/tags/packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>)

### AI overview

A tutorial on enabling and using the Debian 12 Bookworm Backports repository. It covers configuring the repository, updating package lists, searching for packages, installing selected backported packages, listing installed backports, and removing them.

### Source excerpt

The Debian Linux 12 backports repository offers updated versions of software packages for Debian Stable releases. These packages are sourced from Testing (and sometimes Unstable) branches of Debian, and then optimized and recompiled to function on the current Stable release, such as Bookworm. Let us see how to install and use Debian Linux 12 "Bookworm" Backports repository. Love this? sudo share_on: Twitter - Facebook - LinkedIn - Whatsapp - Reddit The post How to enable Debian 12 Backports repository appeared first on nixCraft.

## 100 days of postmarketOS

DevFeed: [100 days of postmarketOS](<https://devfeed.tech/articles/100-days-of-postmarketos-41674.md>)

Original publisher: [Read original article](<https://postmarketos.org/blog/2017/09/03/100-days-of-postmarketos/>)

Published: 2017-09-03T00:00:00Z

Content type: article

Language: en

Sources: [postmarketOS Blog](<https://devfeed.tech/sources/postmarketos-blog.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [Software](<https://devfeed.tech/topics/software.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [Android](<https://devfeed.tech/topics/android.md>), [qemu](<https://devfeed.tech/topics/qemu.md>)

Tags: [alpine-linux](<https://devfeed.tech/tags/alpine-linux.md>), [android](<https://devfeed.tech/tags/android.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [developers](<https://devfeed.tech/tags/developers.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [linux](<https://devfeed.tech/tags/linux.md>), [postmarketos](<https://devfeed.tech/tags/postmarketos.md>), [software](<https://devfeed.tech/tags/software.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>)

### AI overview

A 100-day progress report on postmarketOS, an alternative Linux-based mobile operating system built by adapting Alpine Linux rather than forking Android. The project uses small Alpine packages, aims to minimize device-specific maintenance, and includes QEMU support for experimentation and development.

### Source excerpt

Sustainable Approach For Linux on Phones We are building an alternative to Android and other mobile operating systems by not forking but bending the time-proven Alpine Linux distribution to fit our purpose. Instead of using Android's build process, we build small software packages that can be installed with Alpine's package manager. To minimize the amount of effort for maintenance, we want every device to require only one device-specific package and share everything else. At this point our OS is only suitable for fellow hackers who enjoy using the command-line and want to improve postmarketOS. Telephony or other typical smartphone tasks are not working yet. Why We Evolve in Many Directions Why don't we focus on one "flagship" device and stop making blog posts until it can be used as daily driver? Our philosophy is that community-based FLOSS projects need to become known during the development phase to fellow developers. Our way of doing that is through periodically posting reports summarizing our real progress. The postmarketOS community is a collective group of hackers who contribute to this project in their free time. We won't tell someone who wants to, for example, extend postmarketOS to run Doom on their smartwatch that their idea has no benefit to the project's vision. Such activities demonstrate the flexibility of postmarketOS and oftentimes leads to improvements to the project's codebase as new requirements are implemented to cover previously unforeseen use cases. In addition, these fun activities also increase our collective knowledge about the software and hardware we work with. But most importantly we don't want to, or plan to, take the fun away. Because without being fun and rewarding, a free time project becomes a dead project. It's not all about running Doom though, there are also individuals in the project who have the most fun by actually bringing the project towards this daily-driver vision. Read on to learn about both the incredibly beneficial effor

## Debian Repository Manager

DevFeed: [Debian Repository Manager](<https://devfeed.tech/articles/debian-repository-manager-40682.md>)

Original publisher: [Read original article](<https://radek.io/posts/dr/>)

Published: 2014-05-12T00:00:00Z

Content type: tutorial

Language: en

Sources: [Radek Pazdera](<https://devfeed.tech/sources/radek-pazdera.md>)

Topics: [Debian](<https://devfeed.tech/topics/debian.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Repositories](<https://devfeed.tech/topics/repositories.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>), [Git](<https://devfeed.tech/topics/git.md>), [qemu](<https://devfeed.tech/topics/qemu.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [git](<https://devfeed.tech/tags/git.md>), [less](<https://devfeed.tech/tags/less.md>), [manage](<https://devfeed.tech/tags/manage.md>), [manager](<https://devfeed.tech/tags/manager.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [repository](<https://devfeed.tech/tags/repository.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>)

### AI overview

The article introduces dr, an open-source Ruby tool for setting up and managing small Debian repositories. It provides a unified interface for repository setup, package building, versioning, distribution, signing, and release management, with Git integration and support for tools such as reprepro, debhelper, debuild, and qemu.

### Source excerpt

Set up and manage your own Debian repository with less effort

## Making Your Local Hadoop more like AWS Elastic MapReduce

DevFeed: [Making Your Local Hadoop more like AWS Elastic MapReduce](<https://devfeed.tech/articles/making-your-local-hadoop-more-like-aws-elastic-mapreduce-20844.md>)

Original publisher: [Read original article](<http://themodernlife.net/emr/hadoop/2014/01/02/making-local-hadoop-more-like-emr/>)

Published: 2014-01-02T11:21:13Z

Content type: tutorial

Language: en

Sources: [Ian Hummel](<https://devfeed.tech/sources/ian-hummel.md>)

Topics: [Hadoop](<https://devfeed.tech/topics/hadoop.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Homebrew](<https://devfeed.tech/topics/homebrew.md>), [Development](<https://devfeed.tech/topics/development.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Compression](<https://devfeed.tech/topics/compression.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [aws](<https://devfeed.tech/tags/aws.md>), [compression](<https://devfeed.tech/tags/compression.md>), [config](<https://devfeed.tech/tags/config.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [dev](<https://devfeed.tech/tags/dev.md>), [emr](<https://devfeed.tech/tags/emr.md>), [hadoop](<https://devfeed.tech/tags/hadoop.md>), [install](<https://devfeed.tech/tags/install.md>), [local](<https://devfeed.tech/tags/local.md>), [s3](<https://devfeed.tech/tags/s3.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [unix](<https://devfeed.tech/tags/unix.md>)

### AI overview

This tutorial explains how to configure a local Hadoop environment to more closely match AWS Elastic MapReduce. It covers using s3:// URIs, embedding AWS access keys, enabling transparent LZO compression, and installing Hadoop with Homebrew, including the distinction between s3:// and s3n:// handling in HDFS.

### Source excerpt

At MediaMath we're big users of Elastic MapReduce. EMR's incredible flexibility makes it a great fit for our analytics jobs. An extremely important best practice for any analytics project is to ensure your local dev and test environments match your production environment as much as possible. This eliminates the nasty surprise of launching a job that takes hours only to discover that it fails late into the run due to some unmet dependency or config mistake. Failing to invest time in the dev/test phase is a surefire way to blow big $$. Lately I've been investigating some configuration settings you can make to your local Hadoop to bring it inline with what you'll find when you run a job on an EMR cluster. This is especially important to us since we use S3 as a sort of centralized filesystem and EMR is designed to work wonderfully with S3. Specifically: Using s3:// URIs everywhere instead of s3n:// URIs Embedding AWS access keys Supporting transparent LZO compression Installing Hadoop I run all my Hadoop jobs on my laptop using Homebrew. Homebrew is a fantastic package manager for OS X that makes it a breeze to install general UNIX utilities as well as more complicated software packages (like Hadoop and Hive). $> brew install hadoop And you're good! s3:// vs s3n:// URIs in HDFS Ever wondered what the difference between an s3:// URI and an s3n:// URI is? Essentially up until December, 2010 S3 had a 5GB object size limit. So, if you used the default S3 HDFS implementation (by specifying an s3n:// URI) you couldn't read/write files greater than 5GB. That said, when you did read or write a file with HDFS there was a 1 to 1 correspondence with the object that got stored in S3. To process files larger than 5GB you had to use s3:// URIs in HDFS which actually chunked the file into multiple pieces behind the scenes before storing each piece as a separate object in S3. So when accessing something via HDFS with an s3://bucket/object URI you might actually be downloading multiple