🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
🆕 The Awesome GitHub Copilot project has a new home.
Head over to explore hundreds of community-built customizations:
🔍 Full-text search for agents and skills
📚 A dedicated Learning Hub
⚡ 1-click plugin installs for Copilot CLI & @code
Built by the community, for the community. Check it out.👇
https://t.co/OUL39XaFq4
@odd_joel thanks for great advice. Use mosh I need to use blink shell which will cost some money, currently I am happy with termius + tmux for free, I will reconsider when I have more budget.
Here is my current vibe coding workflow all can do from phone without toching PC
1. Input idea and make claude opus write design
2. Request gpt5.4 to review the design
3. Claude Opus fix desgin and write details design in markdown
4. Request open claw fully implement it.
instead of spending 100$ on claude max I divided my budget as follow 20$ for chatgpt plus, 20$ for claude pro,10$ for github copilot. That way I can try and evaluate many tools. Codex and Copilot can also be used with open code and pi. So now I’m thinking how effectively use them
Introducing Kimi Code, an open-source coding agent under the Apache 2.0 License.
🔹 Python-based, easy to extend.
🔹 Fully transparent — clear, safe, reliable.
🔹 Seamlessly integrates with VS Code, Cursor, JetBrains, Zed, and more.
🔹 Fully-featured & out-of-the-box ready. Switch over in seconds.
🔹 Native Multimodal support
Experience it with Kimi K2.5.