The @GitHub compromise happened through a VSCode extension. While there are plenty of valid places to point blame here, I think the fact that the search ranking of extensions is damn near random is a big contributor. Unverified rando ones often rank higher than perfect matches
SECURITY ADVISORY — TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
• Rotate cloud, GitHub, and SSH credentials immediately
• Audit cloud audit logs for the last several hours
• Pin to a prior known-good version and reinstall from a clean lockfile
Detection — the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
We're hiring.
The @a16z new media team is looking for a showrunner/EP to launch a16z Originals, a YouTube native editorial series with a techno-optimist POV. Episodes will run 10 to 20 minutes and geared for an audience beyond tech.
If you know someone, DM me or send an email.
can ai agents invent writing on their own? recent pet project: 2 agents share a world but each sees only half. their only communication: 7×7 pixel glyphs. they develop symbols, build theories of meaning, and evaluate their own writing. no convergence yet but fascinating to watch!
can ai agents invent writing on their own? recent pet project: 2 agents share a world but each sees only half. their only communication: 7×7 pixel glyphs. they develop symbols, build theories of meaning, and evaluate their own writing. no convergence yet but fascinating to watch!
I found myself getting frustrated with remembering exactly what build/deploy/dev harness I used for each little project, and so I created a tiny `how` cli to solve the problem and I love it
I feel extremely validated about coaching people to avoid using the "you are an expert" prompting technique for years.
Speak to your agent like you would a trusted friend. Consider where you want its inference to come from in its training: respectful, productive conversations.
I need a list of people to follow here.
Every single recommended post on my feed currently is the most hyperbolic “x company just KILLED y industry” bullshit I’ve ever seen.
I want measured thinkers, nuanced takes.
Interests: AI, automation, makers, stage tech
If you think Claude killed Openclaw you clearly don’t understand Openclaw.
People don’t use Openclaw because it can perform tasks for them autonomously across devices. They use Openclaw so they can post about it online.