๐จ BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem.
The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
GitHub was many people's dream job. Partly because employees were encouraged to speak publicly about the company, we could fly anywhere for conferences and company would cover all costs. IMO that's what GitHub should do now, let employees talk about what is going wrong there.
Welcome home Reid, Victor, Christina, and Jeremy! ๐ซถ
The Artemis II astronauts have splashed down at 8:07pm ET (0007 UTC April 11), bringing their historic 10-day mission around the Moon to an end.
Introducing Muse Spark, the first in the Muse family of models developed by Meta Superintelligence Labs.
Muse Spark is a natively multimodal reasoning model with support for tool-use, visual chain of thought, and multi-agent orchestration.
Muse Spark is available today at https://t.co/wHkMPH82ZH and the Meta AI app. Weโre also making it available in private preview via API to select partners, and we hope to open-source future versions of the model.
Learn more: https://t.co/PloE9q5x96
1/ today we're releasing muse spark, the first model from MSL. nine months ago we rebuilt our ai stack from scratch. new infrastructure, new architecture, new data pipelines. muse spark is the result of that work, and now it powers meta ai. ๏ฟฝ๏ฟฝ
America is over $39 TRILLION in debt. If it were up to DC politicians, nothing would EVER change. This is unsustainable!
President Trump wants a balanced budget โ and Iโm fighting to help MAKE IT HAPPEN so our kids and grandkids have a strong future!
This has become a real pattern -- incident happens, then 48 hours later a dozen vendors publish "detections" that are clearly just someone else's research blog post run through an LLM.
It's genuinely bad for the industry because it makes it harder for defenders to know who to trust.
FWIW, the way to tell: ask when the detection fired and whether a human was in the loop.
For example, Socket ingests every npm package at publish time and scans it automatically. [email protected] was published at 23:59 UTC; our system flagged it as malware at 00:05 UTC -- six minutes, no human involved.