Take care of your appearance. Lift the weights. Eat healthy foods. Sleep like an athlete. Dress like you care. Fix your posture. Moisturize your face. Take care of your skin. Your looks are your business card. Make it look like you care about yourself.
Life is too short to worry about little things. Have fun. Fall in love. Regret nothing, and don't let people bring you down. Study, think, create, and grow. Teach yourself and teach others.
Take a skill only 2M people could do. Build for the 260M who couldn't.
That's how the most successful products in Silicon Valley are being built right now.
Canva did it with design. Harvey did it with law. Vibe coding tools did it with engineering.
Someone published an npm package called everything that depends on every public npm package. Then tried to delete it. npm said no. Trapped by his own prank 💀
https://t.co/Efsdal2Dnq
https://t.co/cW8Belhx6o
https://t.co/lNj7cwQib8
🤨 People keep asking how to protect yourself.
#1: set min-release-age=7 in .npmrc
#2: install Socket for GitHub (it's free!) to protect PRs from bad dependencies: https://t.co/D9bsRJj65R
#3: install Socket Firewall (also free!) to protect your laptop: https://t.co/u1NRD57PQ8
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.