


Gene Kim
51.3K posts

@RealGeneKim
WSJ bestselling author: Unicorn Project! DevOps researcher/enthusiast. Coauthor: Phoenix Project, Accelerate. Host of The Idealcast. Tripwire founder. Clojure.











Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.

1/ Yesterday I published a letter to our customers and investors about GitLab Act 2. The agentic era is the largest opportunity in our history. We're making the structural and strategic decisions to meet it. A thread on what changes, what doesn't, and what we're betting on. 👇 about.gitlab.com/blog/gitlab-ac…


‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.


Idea: Business owners should crowdsource a list of Most Hated Software and then indiehackers should pick thru and make new clones of them are just "simple" - rewind 10 years of enshittification on them. I hate (and use): - dropbox - gusto - zoom - loom - canva - accel - most of gsuite - substack - descript - youtube

Apple does this and y’all love it. sudo powermetrics --samplers cpu_power and see it yourself. Let windows cook


