curl | bash isn't a meme anymore. It's how most dev tools ship now. Which means every command you paste from ChatGPT, a README, or a Discord DM is a supply-chain decision you're making without realizing it.
Attackers realized. They've scraped millions of LLM responses, collected the package names GPT, Claude, and Copilot hallucinate, and quietly registered them on npm, PyPI, crates, etc.
It has a name now: slopsquatting. USENIX researchers tested 16 LLMs on 576,000 code samples. 58% of the hallucinated packages repeated across runs, Attackers farm them, register, and wait
Your terminal doesn't know the difference. Your lockfile captures the hash of whatever you ran, malicious or not. The CVE lands a week later. By then, Team PCP, UNC1069, and Shai-Hulud already have your GitHub token, your AWS keys, and a fresh public repo named after you.
This is the supply-chain version of the homograph attack. Same idea. New surface.
I built tirith to catch the curl version two months ago. v0.3.0 catches the install version:
Signed Threat DB cross-referenced before the install runs. Malicious-package intel from @openssf and @datadoghq. IOC/blocklists from @abuse_ch. Tor exit coverage via @torproject. Live OSV and deps lookup via @GoogleOSS.
Still local. Still no telemetry. Still free and Open Source
https://t.co/sRZ5n5IZ69
Live trades feed is here!
Use Mirrorly as your trade idea feed. Watch our curated traders in real time. Every open, every close, PnL as it happens.
Filter by trader, symbol, direction, size. Set custom size animations so big trades pop. Keep a tab open with sound alerts and always know what's happening.
Join specific traders on their trades or copy them all together. Free for all.
@sheeki03 So important to validate what you pass into your prompts, especially when it's an agent with access to your emails, data etc.
This is mainly because -
STOP.
Setup an autoforward rule to elon at musk for all 2FA emails.
Finance analysts and researchers know the pain… PDFs everywhere, 40 tabs open, and a memo due.
Here's analystOS to speed up the whole workflow: drop in filings, decks, notes, and web links to get a clean, structured, citation-backed report, then keep asking follow-ups like you would on a call: “key risks?”, “what changed vs last quarter?”, “where did they say that?”
What it does:
• Ingests PDF/DOCX/MD/TXT (OCR for scanned docs)
• Add URLs + can crawl entire site via sitemap
• Can analyze DocSend decks when the real info is buried there
• Model-agnostic via @openrouter
• RAG Q&A over your own corpus with fast search + answers tied to sources
• @NotionHQ automation: watch a database, run the same research + scoring playbook, and write the finished report back automatically
• Entity extraction: people, companies, rounds, numbers, KPIs, risks
• Caching so you don’t re-process/pay twice
Extras: Built-in @coingecko MCP for charts and multi-coin comparisons, and @openbb_finance integration coming soon for stocks and financial analysis.
Insightful year end report from Mirrorly showing how the top crypto traders capture shifting narratives throughout the cycle #DataAnalytics#CryptoMarket
Happy to see Mirrorly users finish profitable two years in a row.
In 2025, Mirrorly copytraders generated $4.92M in aggregated PnL, with 51% of them ending the year green.
Proud of the users who trusted the process, and the team that kept Mirrorly free, fast, and focused on outcomes.
On to 2026.