I've been busy reworking the levels from the scratch and designing a lot of new characters for the further story line and struggling a bit with self doubt and motivation.
This what level 2 looks like now. ☺️
#solodev#GodotEngine#indiedev#indiegame
Jeff Bezos capped his salary at $82,000. Not because he's modest or because he wanted what's best for society and his company but because salaries are taxed.
Instead, he borrows against his $230 BILLION stock to fund his lifestyle UNTAXED No paycheck = no income tax.
The he jumps on TV and said he pays his fair share of taxes. They think we're stupid.
I'm not gonna lie, the @Meta layoffs are some of the most dystopian I've ever seen. They got told to work from home, they were sent the emails at 4AM in the morning. Those who weren't impacted have software on their computer that tracks their every move, preparing AI to take their job as well. They're literally training the AI that will eliminate their position as well.
Meanwhile, Meta is raking in RECORD PROFITS.
I am a massive, unapologetic AI enthusiast. Yet, this is NOT the future I had in mind.
I wish for Meta to crash and burn. This is not the way. Literally nobody benefits from this.
Tower defense but you're not stuck behind a menu. You move, you fight, you place structures. Lowpoly 3D, rat mutants, hive hearts, caves. The loop is TD, the feel is third-person action.
Still early. Still wip.
#godot#indiedev#gamedev#lowpoly#towerdefense#solodev#wip
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you.
The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads.
The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate.
Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
Hey @StayAtHomeDev and @colosoglobal, I messaged you three days ago asking you to remove my name from the student review section of your paid course immediately. You acknowledged it was wrong on Thursday and promised to fix it. It's still there, three days later, during your launch sale.
You used an old comment I left on a public YouTube video and took it out of its context to make it look like I'm personally recommending your "class" before it's even available. I can't speak for @uheartbeast and @ThisIsDarkDax, but regardless, their comments look like they've been taken out of context too. Apart from being misleading to your customers, it's a false attribution.
You understand this should have been considered an urgent website update, right? Because it's making real people appear as though they said things about your product that they didn't. It's not something you let slide over the weekend during a sales campaign before taking it down.
It's your choice to base your $200 video course on a free and publicly available demo, environment, models and characters that we released under CC-By 4.0. But it's pretty sketchy to vaguely list "assets" as a course perk and a "special gift from StayAtHomeDev". Then it's a whole different level altogether to make it sound like we also endorse the product.
Remove the comment and GDQuest's logo immediately.
There's room for everyone in education, Godot, and gamedev to get honest recommendations and keep competition healthy and ethical.
P.S. Thanks for the creative commons attribution in thin grey font at the bottom of a section dedicated to your own portfolio and only after I mentioned the license. Much appreciated.
Good Morning from Germany, where electricity prices are now regularly falling below zero around midday. On May 1, they even dropped to the floor at -49.999 cents per kilowatt hour. The reason is simple: we are generating more solar power than we can use or store. As a result, Germany has to cover the gap between these negative market prices and the guaranteed feed-in tariffs paid to producers—an expensive outcome. These prices are a clear indication of the utterly disastrous energy transition.
Louisiana’s GOP governor just declared a STATE OF EMERGENCY to CANCEL an election.
Not for a storm — but to redraw maps so he can ERASE a historically Black district.
They’re not even hiding it. MAGA is rigging elections to silence YOU.
🌿 The player drops in.
Grapple, jump, fall through hive hearts, creep swarms, flickering bellflowers.
The world was alive. Now something's moving through it. 🖤
#gamedev#godot#indiedev#darkfantasy
🌑 The hive breathes. The creep spreads. And now something fights back.
First playable look — hive hearts pulse, creep swarms, bell flowers flicker in the dark.
Still early. Still alive. 🖤
#gamedev#godot#indiedev#darkfantasy
Working on a dark fantasy concept. Hive hearts that pulse in the shadows, creep that spreads like a living plague, enemies that rise from the dark.
Early concept stage, but it's already alive.
#gamedev#godot4#indiegame#darkfantasy#indiedev
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
I mean, how the hell is this even legal?
Was it part of the contract that the seller is entitled to say “screw you and the money you've paid us, we're talking these weapons for ourselves”?