
James Ward
10.1K posts

James Ward
@JamesWard
My book: https://t.co/QGevhw6nyE | My podcast: @HappyPathProg | @AWSCloud Agent Experience | @AgenticAIFdn TC | My opinions are mine








🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading. Newly confirmed compromised artifacts: @opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads) mistralai: 2.4.6 on PyPI guardrails-ai: 0.10.1 on PyPI additional @squawk/* packages on npm guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.pyz, writes it to /tmp/transformers.pyz, and runs it with python3 without integrity verification. The git-tanstack.com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds Regardless I just came to say hello :^)” The page also linked to a YouTube video and you can probably guess which one.












I’d have thought it was obvious that features that make semantics lexically apparent to humans also make semantics lexically apparent to LLMs. Put another way, the closer you get to “if it compiles, it works,” the better for agents of all kinds.




