#Anthropic just announced the roll out of an invisible text watermark for Claude. The words are chosen to create a statistically detectable pattern that can only be verified using their secret key.
Learn more : https://t.co/oVhygaIBYj
#AI#Claude#LLM
We are using @coderabbitai for our code review, and it's fantastic! It's free for OSS and offers a free trial for the proprietary code. Check it out: https://t.co/0xg328LbEa
In Case you are not doing it yet, Treat your data pipelines, schemas, and transformations like real software. Version them. Test them. Review them. Deploy them with CI/CD.
Because data deserves the same engineering discipline as the apps that consume it.
#DataEngineering
@derekhalpern We're so confident in what we build that we’re happy to run a milestone-based trial, you only pay once you approve the delivered work. Let us know if you'd be open to a quick chat!
@derekhalpern Since we’re expanding our reach and focused on showcasing our expertise, we’re open to helping you build or refine your setup super affordably just to prove what we can do. No multi-year traps or pricing games just clean data infrastructure that actually works for your ROI.
@Joi2James We are building a professional service provider to support SMEs in their Data and AI Journey without having to pay a fortune
https://t.co/qHPrGUNQip
@lightsilver323 We are building a professional service provider that support SMEs with their Data and AI Journey without having to pay a fortune
https://t.co/12C7zzdope
🚨 Active supply chain attack on npm: keyv and cacheable are compromised right now, and the payload is a worm.
The maintainer account behind both package families was compromised. On August 4, ten packages were republished with a malicious preinstall hook that steals your credentials, then uses those credentials to publish itself into more packages. Malicious versions are live on npm as I write this.
These are foundational packages. keyv, cacheable, flat-cache, and file-entry-cache sit deep in dependency trees as transitive deps of common tooling like ESLint. Tens of millions of weekly downloads. Most affected users never installed them directly.
What the payload does:
• preinstall hook (setup.mjs) downloads a standalone Bun runtime and runs the second stage under it, sidestepping the host Node version and any Node-level monitoring
• Harvests cloud and CI credentials: AWS/GCP/Azure keys, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC, and npm tokens
• Repackages other npm packages with the same hook and republishes them through npm OIDC trusted publishing. This is what makes it a worm.
• Exfiltrates over DNS and by committing stolen secrets to attacker-created GitHub repos
• Plants autostart hooks in .claude and .vscode that execute when a developer or an AI coding agent opens the cloned repo. No npm install required.
The detail worth sitting with: [email protected] shipped with a passing npm provenance attestation. The build pipeline faithfully attested a source that was already trojanized. Signature verification alone did not stop this.
Socket’s AI scanner flagged the malicious setup.mjs hook. If you install anything in the keyv, @keyv, or cacheable scopes:
• Pin to the last known-clean version and rebuild lockfiles by integrity hash. No caret or tilde ranges, no npm update.
• Better: block the entire keyv, @keyv, and cacheable scope at your registry proxy until the account is confirmed clean.
• Rotate and revoke every credential reachable from any host that ran install scripts. npm and GitHub tokens should be revoked, not just rotated.
Developing story. Socket is updating the affected-package list as new versions appear.
Full research report with IoCs: https://t.co/dyjGuLQ5Op
If you are dealing with this right now and want help, email [email protected] and we will spin up emergency white-glove assistance.
Hello 👋
We are looking to connect with business owners who are looking to modernize their Data infrastructure and utilize AI.
Come Visit our website https://t.co/I9ioOEbNhz
Hello 👋
We are here to support companies building modern data platforms as a code for the AI era integrating AI agents, analytics pipelines, and decision-ready infrastructure into the tools they already use. Just engineering. Just results.