VoidZero, the team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare. Vite stays open source, vendor-agnostic, and built for everyone. https://t.co/DJTpX4Q9Xt
A malicious was payload found that installs a persistent token monitor as a systemd/LaunchAgent service. It polls your GitHub token every 60s - if revoked, it triggers destructive file deletion.
You should verify if you're affected BEFORE revoking your token:
Linux:
ls ~/.local/bin/gh-token-monitor.sh
systemctl --user list-units | grep gh-token-monitor
macOS:
ls ~/Library/LaunchAgents/ | grep com.user.gh-token-monitor
If found, disable the service first, then revoke.
https://t.co/b9Bz38mfJ4
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you.
The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads.
The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate.
Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
A lot of great people at Cloudflare recieving some pretty terrible news today. Hire these people, they're the best group of folks I've ever worked with. 🧡
Stop building laggy voice bots!
We’re hosting a hands-on workshop to build a voice agent that actually listens and remembers.
With the Cloudflare Agents SDK & Workers AI, we’ll implement Streaming STT/TTS (Deepgram Nova + Kimi), Interruption handling, Voice-triggered tool calls all with zero external API keys.
Join @fayazara on April 23, 4 PM SGT for a live hands-on workshop. Register here: https://t.co/JojeZLNFXY
Imagine a pocket “hacking” AI agent built for hardware security, which continuously scans your surroundings using RF, Sub-Ghz, Bluetooth, WiFi, etc and identifies plugins and writes modules on the fly to attack devices around you! Join waitlist on https://t.co/nFFkP6P9LW today.
@opencode@GrowthX_Club
We are launching Flagship, a native feature flag service built on Cloudflare’s global network to eliminate the latency of third-party providers. https://t.co/gtu5xwSVCa
Rollout complete!🏁
Introducing Flagship: @Cloudflare's native feature flag service built for the AI-first world. OpenFeature compatible, evaluated across region Earth🌐
Why we built it 👇
https://t.co/Fe4S6wK1VD
An AI agent can write your code in minutes. But someone still has to review, merge, deploy, and monitor it.
What if the agent could do that too?
Feature flags are the missing piece. They let an agent ship code behind a flag, test it on real traffic, ramp the rollout, and kill it instantly if things break.
No human in the loop until you choose to be.
Today we're shipping Flagship to make this possible - feature flags native to @Cloudflare's network, OpenFeature standard.
Move fast, break nothing.
https://t.co/UYWTNO182f
India 🇮🇳 — your Android community is getting back together.
📅 Nov 20
If you’re building, learning, and shipping with Android… you’ll want to be here.
👉 Learn more: https://t.co/NYcavHsbku
Me @roerohan and @Paramssharma have been tinkering with this idea for some time and we finally made it
Introducing Sidekick - a tiny ai companion that lives in your menubar and is always available
Pick from hundreds of AI models or bring your own AI Gateway with @CloudflareDev