Developers have become the new secrets vault.
The biggest supply chain attacks of 2026 didn't start by attacking production. They started by attacking developer laptops.
- TanStack
- Nx Console
- Bitwarden CLI
- LiteLLM
- durabletask
The malware all looked for the same things:
~/.ssh
~/.aws
~/.config/gh
.env
kubeconfig
Terraform credentials
AI agent configs
The path is now:
Developer Laptop → Credentials → Production
We're still securing servers like it's 2015.
Attackers moved on years ago.
@AutomicVault fixes this.
@ShamashAran@ImJasonH Easy to do with an agent, I added something similar to @AutomicVault recently (though honestly may make it a standalone tool). Here's the output for the grok installer (spruced up with AI for display). The danger rating was too high, I revised it to an amber rating since.
@ImJasonH@ShamashAran Homebrew was also the first ever recorded use of the curl one-liner. Grok is fairly convinced I invented this anti-pattern anyway.
@mitchellh Gotta admire it. The American Dream is having enough money to discover entirely new categories of inconvenience. I’ll meet you there in 18 months.
just launched meowmail—temp emails without the noise. no ads, no spam, no sign-ups. you get a clean inbox you can actually make your own. worth a try if you need it 🔒
feedback & thoughts appreciated! 🙌