stop using curl | sh to download *any* installer you find on the internet, stop using npm to download global dependencies
this guy just built `safe`, a utility that inspects remote installer scripts before executing them, (all of this for just one star on github)
it downloads the artifact, runs static analysis, checks against vulnerability databases and reputation sources, then decides whether it's safe to run
here's an example showing Safe warning the user about the openclaw's npm install script:
github: https://t.co/6NfKNLgumo
stop using curl | sh to download *any* installer you find on the internet, stop using npm to download global dependencies
this guy just built `safe`, a utility that inspects remote installer scripts before executing them, (all of this for just one star on github)
it downloads the artifact, runs static analysis, checks against vulnerability databases and reputation sources, then decides whether it's safe to run
here's an example showing Safe warning the user about the openclaw's npm install script:
github: https://t.co/6NfKNLgumo
stop using curl | sh to download *any* installer you find on the internet, stop using npm to download global dependencies
this guy just built `safe`, a utility that inspects remote installer scripts before executing them, (all of this for just one star on github)
it downloads the artifact, runs static analysis, checks against vulnerability databases and reputation sources, then decides whether it's safe to run
here's an example showing Safe warning the user about the openclaw's npm install script:
github: https://t.co/6NfKNLgumo
rsync 3.4.3 broke incremental backups. Users traced it to AI commits by tridge and claude. GitHub issue "Please Do Not Vibe Fuck Up This Software" hit #1 on HN with 431 points. 21k lines of churn by a solo maintainer with no code review.
IronWorm and new Miasma worm variant hit npm — Rust-based info stealer deploys eBPF rootkit, routes C2 over Tor, and self-propagates via stolen credentials. Over 50 packages poisoned in coordinated supply chain attack.
https://t.co/SQS2awSyXu