this presentation made by claude code UNDER 10 minutes using @zarazhangrui's https://t.co/37d46dHrdu and my blog post https://t.co/jxaVX5si5f is just so pretty!
thinking of ways to import this into google slides or sth so that team collaboration can happen
SECURITY ADVISORY โ TanStack npm packages
A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package.
Status: ACTIVE โ packages are deprecated, npm security engaged, publish path being shut down.
Severity: HIGH โ payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys.
If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised:
โข Rotate cloud, GitHub, and SSH credentials immediately
โข Audit cloud audit logs for the last several hours
โข Pin to a prior known-good version and reinstall from a clean lockfile
Detection โ the malicious manifest contains:
"optionalDependencies": {
"@tanstack/setup": "github:tanstack/router#79ac49ee..."
}
Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root).
Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level.
Full technical breakdown, complete package and version list, and rolling status updates:
https://t.co/Zy8qG7PA9f
Credit to the security researcher for responsible disclosure.
used @claudeai's playground today to visualize recursion logic for the callstack PR review for https://t.co/0jC9bCxvmz
so helpfulโจ I want to add more for other complex components (invoke contract) to the repo. It might be helpful for other devs
i tried sf a couple of months in 2023, officially moved in 2024 & thinking of settling down here in 2026 b/c i love it so much (after time in nyc, miami, seoul, etc).
how i made friends in sf:
- gym: going to same class, meeting same people, friendship formed organically
- hackathon: hustle on projects together. it turns out one of the girls and i had the same hobby ๐โโ๏ธ, we started surfing every weekend, became bestie (first bestie I ever made in 30s)
- work: met genz bestie and love my colleagues at stellar
- twitter: find irl events, meet cool online peep irl
- host: i hosted and initiated hangouts a lot..
first 6 month was hard though :) so i tote understand. but if tech bubble becomes too much, make sure to make time to do hobbies that aren't tech
6 months ago, I moved to San Francisco.
Itโs the best place in the world to build, and one of the worst places to stay human. My unfiltered take:
1. SF is both overhyped and underrated
The overhyped part: there are a lot of people with incredible resumes who are deeply unimpressive in real life. They were at the right company, at the right time, in the right market, and got carried by the wave. They made money, got comfortable, and now spend their time โexploring opportunitiesโ over coffee, wasting your time.
The underrated part: the top 1% here is insane. But almost impossible to get. Hiring in SF feels like being a guy on a dating app: everyone you want is out of your league, and everyone in your league wants someone out of theirs. The best people have unmatchable packages, endless options, and are optimizing for maximum impact: labs, frontier companies, or startups raising $100M pre-seed rounds.
If you raised $10M from Tier 1 investors, youโre not hot shit here. Youโre a B-player. Itโs humbling.
2. There are fewer mission-driven people than I expected
Especially on the application layer. A lot of people are in โsecure the bag before itโs too lateโ mode. And honestly, it gives me the ick.
The real religious builders Iโve met are often in labs, hardware, biotech, deeptech, defense โ places where the work is hard enough that you canโt fake obsession.
3. The status game favors builders
This is what SF does better than anywhere else. It rewards obsession. It rewards weirdness. It rewards people who make building their entire personality. Europe punishes that. SF gives it status. If youโve felt like an outsider your whole life because you care too much, work too much, think too radically, or refuse to be chill about things that matter, this city will make you feel less insane.
4. The market liquidity is absurd
Even if you donโt build a billion-dollar company, if you manage to build a strong product with a great team, someone smart might still acquire you for $ 100M. Yeah I know, itโs not your dream outcome as a founder, but on the days you feel desperate, it helps to keep going.
5. SF does not care about the meaning crisis thatโs coming
Anyone paying attention here can feel that something massive is happening with AI. But Iโm shocked by how little people talk about the meaning crisis coming next. Everyone wants to talk about AI liberating humanity. Almost no one wants to talk about what happens when work โ the thing that gives most people identity, structure, dignity, status, and purpose โ starts disappearing. The vacuum will not be peaceful. People are underestimating the chaos that comes from humans suddenly having no idea why they matter. And I really feel like no one cares.
6. Personally, Iโve never been more unhappy
I moved to SF and entered the matrix. Iโve always been intense. Iโve always worked crazy hours. But here, I lost the last parts of myself that were not about building.
I donโt go to events. Most networking events feel like theater for people pretending to be important. The only events worth going to are small, curated dinners with people who are actually alive. Iโve made 0 real friends. I donโt do well with transactionality. I donโt do well with people constantly performing greatness. I donโt do well with rooms where everyone is optimizing and no one is being honest.
So yes, SF is lonely, transactional, delusional, addictive, inspiring, boring, extraordinary, and completely insane.
But it is still the only place to be right now if youโre a founder trying to build the next wave of humanity.
And for now, thatโs enough.
catching up on stripe sessions day 1 key note!
agentic payment (via link) and stripe console (ai agent for a stripe account) will be so useful. stripe is also expanding their terminal (in person payment) to 15 more countries
the first stripe terminal i saw was in berlin ๐ฉ๐ช in 2024 then i used it again most recently in coconut grove, miami last week!
it'd be cool if stripe console can work with both online and in person payments (should be opt in ofc)
i am obsessed with this new thai restaurant in sf:
"Sawaan Thai Kitchen" in mission!
lemongrass catfish, drunken noodles, cloud ring, golden massaman chicken curry - omg so good!
don't order spicy unless you love extra spicy. their 'medium' was already spicy to me
@jeffreyhuber i watched my non technical instagram influencer friend using claude cowork. she kept getting errors irrelevant to her request (find a specific word in her msgs). She got very frustrated with ambiguous error message
she liked claude's chrome extension for her work though