
angus keatinge
948 posts

angus keatinge
@anguskeatinge
I run a fintech, my wife runs my life




SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.



The incidence of pronouns in social media bios and email signatures is down at least 70% since the peak in 2020.



Australian Government to DOUBLE the tax on every young Australians success in next week’s budget. #budget2026 Young Australians building real wealth are about to get absolutely fleeced by @AlboMP and @JEChalmers. They want to double the tax on your life’s work. This isn’t “fairness.” It’s a brutal raid on every Australian trying to build real wealth. #LaborTaxRaid



Kim Kardashian has reportedly decided to end her pursuit of a law degree after failing the bar exam 3 times.





Google Chrome is quietly downloading a roughly 4 GB AI model to many users’ computers without clear upfront consent. The file, called weights.bin, is part of Google’s Gemini Nano on-device language model and lands in the browser’s user data folder under OptGuideOnDeviceModel. It powers built-in AI tools such as “Help me write,” smarter tab suggestions, on-device scam detection, and page summarization. The download triggers automatically for devices meeting minimum hardware requirements, and Chrome often replaces the files if deleted. While the model processes data locally, installation happens in the background with minimal notification. The scale is noteworthy. Hundreds of millions or billions of installations add up to thousands of tonnes of carbon emissions globally from data transfer, even though each is a one-time event. To prevent or remove it, go to chrome://flags, disable the entries for the optimization guide on-device model and Prompt API, restart the browser, and manually delete the folder.












