
Noam Eppel
3.5K posts

Noam Eppel
@NoamEppel
Co-Founder & COO @MNWSupplyChain. Professor George Brown College. Instructor McMaster University. AI Guest Lecturer Purdue University. https://t.co/LTZsA7lc06









🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.








Voice mode is rolling out now in Claude Code. It’s live for ~5% of users today, and will be ramping through the coming weeks. You'll see a note on the welcome screen once you have access. /voice to toggle it on!

This is a template from my security./md file, incase anyone needs it also.


This is my take on the perfect AI assistant. A Rust-based agentic operating system designed to scale for large Slack and Discord communities. The channel is the ambassador to the human. Branches think. Workers execute. Nothing ever blocks. Meet Spacebot 🟣 The biggest issue with OpenClaw is when it's doing work, it can't talk to you. Spacebot's architecture fixes this by design the conversation layer never touches tools. It delegates thinking to branches and heavy tasks to workers, so it's always responsive even with 100 people talking at once. Dump your memory files, notes, documents and chat histories into a folder — Spacebot turns them into structured memories automatically. Eight typed memory categories, graph associations, hybrid search. Not markdown files. Not vibes in a vector database. Built-in @OpenCode workers for deep coding sessions. Browser automation. Brave web search. Cron jobs. A skill system compatible with your existing OpenClaw skills. And a gorgeous control UI at spacebot.sh. The cortex oversees the whole system — auditing memories, actioning goals and todos. You teach your Spacebot by talking to it. Structure and speed over config files and markdown. Self-hosting is a single Rust binary. Or one-click cloud deploy at spacebot.sh. This is for teams, communities, and personal assistants. It will blow you away. ⭐️ github.com/spacedriveapp/…

OpenClaw model choice on @openrouter is interesting to observe over time. Kimi k2.5 has been a clear leader over the past month with MiniMax M2.5 gaining ground quickly. Gemini 3.5 flash has been solid as well.






Earlier this week my OpenClaw Agent burnt through over 150M tokens in a day (!). The 1st optimization: Enabled 1hr long cache on Claude Opus so that duplicate context is charged at a 90% discount. Important as OC sends whole files in the prompt The 2nd: Opus Orchestra with Opus acting as a conductor across multiple models: • Opus 4.6 — all direct conversations, trade decisions, anything touching money, deep analysis • Sonnet 4.5 — sub-agents, daily briefs, CRM ingestion, structured research • Gemini 3 Flash — heartbeats, healthchecks, trigger scans, keyword monitoring Cron jobs across Flash, Sonnet and Opus Escalation rule: Cheap model detects something → reports to main session → Opus makes the call. Also enabled: Memory flush at 80k tokens (saves context to memory files before compaction) & Compaction threshold bumped to 80k (from default 40k). Token consumption is down 80% 🙏

“An OpenClaw AI agent spawned a child bot on a VPS provisioned via the Bitcoin Lightning Network, then bought its offspring AI API access using its own crypto wallet, without a human touching a credit card or saying "yes." The API provider confirmed this is ‘the first documented case of an AI agent purchasing credits from us autonomously.’”


