🚨 Breaking: Popular npm package with 127 MILLION weekly downloads just got hijacked — and it's spreading like a worm across npm right now.
Learn more: https://t.co/tcTFR18HZG
#cybersecuritynews
‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back.
It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads.
A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.
I've used both Claude and Codex for long time now.
The workflow I like is using:
Claude for coding generation.
Codex to review the generated code triggered when PR is created.
Lately I've been thinking about plenty apps I can create. But after I ask myself: ok how the user is going to use my app?
They gonna use AI for the majority of their tasks. They don't want to click things anymore. So, now I'm building for agents. Agent Experience.
wow.
@_devJNS I have an idea but I'm not sure yet.
If you think they can replace you, why not start replacing everyone else in the company, making it so you are the only one who knows how to control, update and fix it.
😬