Amigos de la CDMX, recuerden seguir estos pasos en cuando suena la alarma sismica:
1. Mantén la calma
2. git add .
3. git commit -m "tenemos sismo"
4. git push -f origin main
5. Busca un lugar seguro
Liftoff.
The Artemis II mission launched from @NASAKennedy at 6:35pm ET (2235 UTC), propelling four astronauts on a journey around the Moon.
Artemis II will pave the way for future Moon landings, as well as the next giant leap — astronauts on Mars.
Google Threat Intelligence Group is tracking an active supply chain attack 🔎
North Korea-nexus actor UNC1069 compromised the "axios" NPM package (v1.14.1 & 0.30.4), deploying the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux.
Learn more: https://t.co/pII35aPpRA
The Vercel security and compute teams have conducted an investigation into the malicious takeover of the 𝚊𝚡𝚒𝚘𝚜@𝟷.𝟷𝟺.𝟷 npm package.
• We’ve blocked outgoing access from our build infrastructure to the Command & Control hostname 𝚜𝚏𝚛𝚌𝚕𝚊𝚔.𝚌𝚘𝚖.
• The malicious version of the package has been blocked and unpublished from npm.
• Vercel’s own infrastructure and applications have been unaffected.
• We recommend checking your supply chain for exposure.
For more information, read the full advisory ↓
https://t.co/o394nzLlCw
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
Si ha sido tu último baile, gracias @Al_Horford. Por años de hacernos feliz, de dejarte la vida por una camiseta y por sentir el verde como piel propia.
Si vuelves otro año, puertas abiertas.
Y ojalá el #42 en el techo.
La mente crea historias que tal vez jamás se harán realidad, pero mientras ahí está uno como pendejo preocupándose de cosas que ni al caso porque todo se trata de la percepción a través de pinches traumas que uno tiene nomás porque creció en los 90 y el chupacabras andaba suelto.