
OpenMatter
398 posts

OpenMatter
@OpenMatter_
Verifiable Collaboration. Computing without Exposure. https://t.co/6mrYtL8Q3M


The "Mini Shai-Hulud" attack on TanStack NPM packages just proved that standard software provenance is fundamentally broken. If an attacker controls your CI runner, they control your attestations. Policy based security is failing at scale. 🧵






🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading. Newly confirmed compromised artifacts: @opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads) mistralai: 2.4.6 on PyPI guardrails-ai: 0.10.1 on PyPI additional @squawk/* packages on npm guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.pyz, writes it to /tmp/transformers.pyz, and runs it with python3 without integrity verification. The git-tanstack.com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds Regardless I just came to say hello :^)” The page also linked to a YouTube video and you can probably guess which one.

1/ AI agents are moving from experiments to production. They’re starting to represent real businesses, handle workflows, and interact with customers. Today, @GoDaddy and HOL published draft specs that help answer: • who is behind this agent? • can its history be verified?









1/ Today we’re launching the HOL Partner Program. Cohort One brings together 30+ signed partners, including XMTP, GoDaddy, and DSR, to help shape open infrastructure for AI agents. Registries. Payments. Privacy. Security. Communication. Standards. The agent stack is forming now.



