Two insightful days at SoDA Conference Poland.
One theme dominated: value - how it's created, delivered, and priced. The pace of change in IT services leaves no room to stand still. Attending annually gives you a front-row seat to all of it. See you at the next edition.
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
If you ever struggled with overbloated context objects in Node.js or Nest.js - there’s a better way.
AsyncLocalStorage + nestjs-cls = cleaner code, easier multi-tenancy, logging & transactions.
Read how 👉 https://t.co/16Lg0cKYY5
🧠 METR (Jul 2025) found experienced devs were 19% slower using AI tools—despite feeling ~20% faster.
Prompting, waiting, and fixing AI outputs added friction.
On #WorldAIDay, let’s focus less on perception—and more on where AI actually fits.
#AI 🔗 https://t.co/iBTsiBNabd
Vue 3.6 is on the horizon. Vapor Mode and Alien Signals push reactivity and rendering to the next level.
We break down how they work and what they mean for real-world apps.
👉 https://t.co/FdVW0fmsBO
#VueJS#Vue3#WebDev#Performance#Frontend#VueConfUS2025
Node.js 24 is here and it's looking good 😎🚀
Featuring updates to V8 v13.6, npm v11, improved Permission Model and more new features in the blog.
Check it out and let us know what you think: https://t.co/oQdo5g6I3N
🚀 Big takeaways from State of AI 2025:
🤖 69% of devs use AI for <25% of code, but 76% refactor most
📝 Surprise hit: docs & comments
👨💻 Copilot & Vercel’s v0 lead
😅 Issues: hallucinations, limits, $$$
🧠 Devs aren’t scared—just cautious
Struggling to mix ESM and CommonJS in your TypeScript projects?
TypeScript 5.8 + Node.js 22 make it clean — no hacks needed.
Learn how to configure seamless module compatibility: https://t.co/LNaawPY5af
#TypeScript#NodeJS#JavaScript#WebDev
Just a reminder: Node.js 23 is now in Maintenance mode.
The Node.js team does not plan to issue further releases for this version.
Node.js 18 will be EOL (End-of-Life) at the end of April.
Please, make sure to update your Node.js versions.
Just back from the SoDA Conference in Łódź! 2 days of insights on AI, global shifts, regulations, and real talk on growth, open source & #SoftwareHouse strategies. Great energy, great people, and a truly welcoming vibe. See you next year! 🚀 #SoDAConference2025
The State of JavaScript 2024 Survey is out! 🥳
We’re excited to see tools like PNPM, Vite, and Vitest growing in popularity—core parts of our workflow. Vue.js is also climbing the ranks, earning well-deserved praise!
#JavaScript#WebDev#StateOfJS
Big shoutout to @GitTown for revolutionizing our workflow! 🙌 With its smart commands for branching, merging, and keeping everything in sync, we’ve streamlined our development process like never before. 🚀 If you’re looking to save time and boost collaboration, give it a try!