
Stephanie So
32K posts

Stephanie So
@ComplicatedIsOK
Bullish on humanity in the morning. On a mission to eliminate central points of failure on the internet. Personal account. Co-founder & CEO of https://t.co/LP0GihbY8Z.





Roughly 5-10% of the global repo turnover depending on the day. app.rwa.xyz/broadridge-dlr That’s just one canton app who has decided to disclose their data. Given your ask for data, will spare you other anecdotes as other apps have to-date opted to remain private - though we expect, to some degree, for that to change over time.




🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.















BREAKING: Anthropic data leak reveals the existence of “Claude Mythos,” a new AI model that reportedly presents unprecedented cybersecurity risks.

















