<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/auditing-vite-dev-servers-for-env-exposure-via-fs-and-the-hmr-socket</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T00:00:00.000Z</news:publication_date>
      <news:title>Auditing Vite Dev Servers for .env Exposure via /@fs and the HMR Socket</news:title>
      <news:keywords>vite, security, javascript, cloud-security, devsecops</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/reading-the-axios-npm-diff-how-a-postinstall-hook-turns-into-ci-rce</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T00:00:00.000Z</news:publication_date>
      <news:title>Reading the Axios npm Diff: How a Postinstall Hook Turns Into CI RCE</news:title>
      <news:keywords>npm, supply-chain-security, ci-cd, javascript, rce</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-a-webauthn-login-flow-for-aitm-proxy-phishing-and-session-token-theft</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-14T00:00:00.000Z</news:publication_date>
      <news:title>Auditing a WebAuthn Login Flow for AitM Proxy Phishing and Session Token Theft</news:title>
      <news:keywords>webauthn, passkeys, phishing, authentication, security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/hardcoded-keys-in-react-native-bundles-scanning-your-own-artifacts-the-way-claude-scanned-18-million-apks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-14T00:00:00.000Z</news:publication_date>
      <news:title>Hardcoded Keys in React Native Bundles: Scanning Your Own Artifacts the Way Claude Scanned 1.8 Million APKs</news:title>
      <news:keywords>react-native, security, secret-scanning, appsec, mobile</news:keywords>
    </news:news>
  </url>
</urlset>
