DevDiary

1.9K posts

DevDiary banner
DevDiary

DevDiary

@devdiary0x

25, Ex-SWE | Vibing until I get my next hustle | Relearning stuff in Public | AI & Tech Navigator | Building @Minmailist

Terminal Bergabung Ekim 2025
269 Mengikuti281 Pengikut
DevDiary
DevDiary@devdiary0x·
@CoderUday Agreed, I feel the same It's annoying and idiotic, these should be permabanned ...Show more
English
0
0
0
26
Uday
Uday@CoderUday·
All these idiots who write "…Show more" at the end of their tweet should be banned
English
3
1
17
382
kanav
kanav@kanavtwt·
npm = neatly packaged malware
kanav tweet media
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
6
2
33
2.6K
DevDiary
DevDiary@devdiary0x·
@VazeKshitij Didi/Bhaiya interns about to raise "fixed ReadMe" PRs
DevDiary tweet media
English
1
0
1
45
kshitij vaze
kshitij vaze@VazeKshitij·
"GSOC ka package" - how brutally has the spirit of open-source been decimated in this nation's student community man! These 3 words beautifully encapsulate the way engineering colleges and the whole method of educating students about CSE have FAILED. And for the clueless - GSOC is NOT a fucking internship, it is NOT a get-rick-quick method, it is NOT anything that you've been told about by your favorite bhaiyya-didis on YouTube.
Shreyaaaa✨@shreyadoesstuff

WHY DID I JUST HEAR THE WORDS "GSOC ka package dekha hai? Tum logon ko nahi chahiye kya wo?" SHUT THE FUCK UP SENIORS.

English
8
2
53
2K
DevDiary
DevDiary@devdiary0x·
@theo I spent like 2 days on HTML and CSS, made beautiful notes back in 2021 I can't believe this whole thing is trivialized(especially for langing pages)
English
0
0
0
403
Theo - t3.gg
Theo - t3.gg@theo·
Can’t believe I spent years learning all the Tailwind class names just to have AI write them for me
English
90
13
499
13.5K
DevDiary
DevDiary@devdiary0x·
@Manixh02 Not at all. It now boils down to taste. Plus security and architecture
English
0
0
0
37
Manish Kumar
Manish Kumar@Manixh02·
Ai is killing every fking field! Is Game development and App development still safe ?
English
24
1
32
2.3K
DevDiary
DevDiary@devdiary0x·
@wholyv There is a reason it's called "artificial" intelligence XD
English
1
0
1
18
lyv ⌘
lyv ⌘@wholyv·
wait until you realise artificial intelligence is not intelligent at all.
English
12
1
11
445
DevDiary
DevDiary@devdiary0x·
@GeekyVaishnavi Popular opinion: One algo change and your reach might die. OR you might run out of ideas. In Google, even if you are kicked out, the name tag is enough to get another job elsewhere. And if you survive layoffs, you can make more money It's not X OR Google It's X AND Google
English
1
1
2
154
Vaishnavi
Vaishnavi@GeekyVaishnavi·
Unpopular opinion: You can make more money on X than working at Google. I just saw someone with 20K followers making ₹2L/month. Yeah… I was shocked too.
English
51
3
117
5.2K
DevDiary
DevDiary@devdiary0x·
Had to wait ~8 hrs to download pmtiles, absolutely worth it
DevDiary tweet media
English
0
1
4
28
kapilansh
kapilansh@kapilansh_twt·
some of the worst things to ever exist - windows laptop - windows laptop with 16GB ram - android phone - android phone with 8GB ram + 128GB storage - claude's $20 plan did I miss anything ?
English
17
3
35
750
DevDiary
DevDiary@devdiary0x·
@tekbog 100% Very few companies have a dedicated sec team And even if they have, they only check for things like leaked credentials, rate limits, access controls, etc Very very rare for CI tooling
English
0
0
1
187
terminally onλine εngineer
the big secret in software engineering is that nobody audits anything, in small or big companies it doesn’t matter, you can have processes and rules and CI tooling to catch specific cases, package analysis, binary analysis, even cybersec on payroll - som1 will just npm i virus
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
23
26
523
25.4K
George Hanu ⚡ Dev. Educator + Builder
@wesbos Nothing unites JavaScript developers like a random package turning into a national emergency 😬 How many teams are about to learn what is buried in their dependency tree today?
English
1
0
90
8.7K
DevDiary me-retweet
Wes Bos
Wes Bos@wesbos·
‼️Do not npm install or deploy anything right now Supply chain attack on axios 1.14.1 - even if you don’t use axios it may be a nested dep. Pin versions or wait until this is resolved
Maxwell@mvxvvll

@npmjs @GHSecurityLab there is an active supply chain attack on axios@1.14.1 which pulls in a malicious package published today - plain-crypto-js@4.2.1 - someone took over a maintainer account for Axios

English
147
1.5K
7.6K
1.1M
DevDiary me-retweet
Vanshika
Vanshika@vanyaSile·
✅ Quick actionable checklist right now: 1. Check immediately: npm ls axios npm ls plain-crypto-js 2. If you see 1.14.1 → Pin safe version: In package.json: "axios": "1.14.0" ← exact version, no ^ or \~ 3. Then: rm -rf node_modules package-lock.json npm install (same for yarn/pnpm) Malicious versions (1.14.1 & 0.30.4) are already being taken down from npm, but any install in the last few hours may be affected. Already ran npm install today? Rotate secrets + check temp folders. Who else found it in transitive deps? Share below 👇 #npm #SupplyChainAttack #JavaScript
English
1
7
58
7.9K
ℏεsam
ℏεsam@Hesamation·
this thing disappeared like smoke in a thunderstorm.
ℏεsam tweet media
English
58
19
1.3K
86.1K
Wes Bos
Wes Bos@wesbos·
Looks like affected versions have been taken down. Back to work. Follow me, Enjoy @syntaxfm
Wes Bos tweet media
English
2
20
155
25K