Confirmed the fuma-content repository was affected by Shai-Hulud:
- it happened likely during the transition to pnpm v11 (which should disable any postinstall scripts unless explicitly allowed), the postinstall script in affected Tanstack Start packages was triggered while pnpm was still v9.
- there's no affected versions of following being published (from what I have verified manually): fuma-content, fumadb, fumadocs. I suspect it's because (1) .npmrc file only contained hoist options (2) pnpm v11 was used since then. (3) I don't use Claude Code. It's possible that I overlooked some versions/packages, but all recently published package versions are manually verified.
- fuma-content is already deprecated, repo history is kept to analyse the cause.
- my machine has finished factory reset, all secrets are revoked, this will cause some sites to break temporarily. Will be back soon once I get more information & some sleep.
Hi @fuma_nama, your repository got compromised with the malicious Shai-Hulud setup script. I encourage you to take quick action
Commit: https://t.co/RILV6UWNTI
❌ Se acabaron los "daños colaterales" de Javier Tebas: el Congreso frena los bloqueos indiscriminados de IPs por parte de LaLiga.
➡️ Tras años de bloqueos masivos sin control, se impondrán límites para que el Internet español no se paralice cada... https://t.co/7VhELVmOtK
This weeks' skills changelog:
- /ubiquitous-language deprecated, use /grill-with-docs instead
- /grill-with-docs for codebases, /grill-me everywhere else
- Skills can now be used with any issue tracker
- Experimental /diagnose and /triage skills
@mattpocockuk it sometimes outputs the options using the super nested labels directly (A2.1.b.i, A2.1.b.ii, A2.1.b.iii, A2.1.b.iv …).
it makes it a bit tough to read and reply to cleanly, although not a big deal
claimed the 100$ credit on cursor's cloud agents to ship even faster 🐐
currently using cloud agents to tackle high impact pending tasks in my backlog, while in parallel I keep building with the desktop app, honestly it feels amazing
a person who commits to something for a thousand days straight becomes a force that most people will encounter once in their lifetime and never forget. a thousand days. hardly anyone can commit to something for thirty. which means the field thins dramatically by day sixty. and by day two hundred you are essentially alone. and by day five hundred the results have started compounding so aggressively that people will use the word talent to describe what is actually just the accumulated residue of a person who refused to leave the room.