André

8.4K posts

André banner
André

André

@atmcarmo

I talk about football, Formula 1, tech. I’m a principal engineer / tech lead / platform engineer.

Porto, Portugal Katılım Haziran 2009
1.3K Takip Edilen1.5K Takipçiler
André retweetledi
rahat
rahat@Rahatcodes·
Claude Code has a regex that detects "wtf", "ffs", "piece of shit", "fuck you", "this sucks" etc. It doesn't change behavior...it just silently logs is_negative: true to analytics. Anthropic is tracking how often you rage at your AI Do with this information what you will
rahat tweet media
English
547
767
14.5K
1.3M
André
André@atmcarmo·
This is a very serious supply chain attack. Please read and avoid this version of axios.
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
0
0
2
303
André retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
533
4.1K
16.3K
11.9M
André retweetledi
Wes Bos
Wes Bos@wesbos·
‼️Do not npm install or deploy anything right now Supply chain attack on axios 1.14.1 - even if you don’t use axios it may be a nested dep. Pin versions or wait until this is resolved
Maxwell@mvxvvll

@npmjs @GHSecurityLab there is an active supply chain attack on axios@1.14.1 which pulls in a malicious package published today - plain-crypto-js@4.2.1 - someone took over a maintainer account for Axios

English
168
1.8K
9K
1.6M
André retweetledi
Autosport
Autosport@autosport·
Fernando Alonso said this before today's race and Ollie Bearman's 50G accident... #JapaneseGP
Autosport tweet media
English
84
2.4K
21.5K
459.5K
André
André@atmcarmo·
@fia You are going to get a driver killed. Stop this now.
English
0
0
1
127
FIA
FIA@fia·
Following the accident involving Oliver Bearman at the Japanese Grand Prix and the contribution of high closing speeds in the accident, the FIA would like to provide the following clarifications. #FIA #F1 #JapaneseGP
FIA tweet media
English
3.7K
2.5K
16K
3.4M
André
André@atmcarmo·
Here we go again. Furar o mesmo pneu duas vezes.
André tweet media
Português
0
0
1
178
André retweetledi
Gergely Orosz
Gergely Orosz@GergelyOrosz·
If you use GitHub (especially if you pay for it!!) consider doing this *immediately* Settings -> Privacy -> Disallow GitHub to train their models on your code. GitHub opted *everyone* into training. No matter if you pay for the service (like I do). WTH github.com/settings/copil…
Gergely Orosz tweet media
English
394
929
5.2K
564.2K
André
André@atmcarmo·
It’s bad when F1 cars loose 50kph on a straight. It’s ridiculous when they loose 50kph on the 130R in Japan. F1 is going downhill and this new regulation is just embarrassing
English
2
0
3
205
André retweetledi
Daniel Hnyk
Daniel Hnyk@hnykda·
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
English
309
2.3K
9.4K
5.6M
André retweetledi
Riley Walz
Riley Walz@rtwlz·
made my computer dramatically play BBC news music before every meeting
English
602
6.3K
71.8K
4.3M
André
André@atmcarmo·
Bednarek é um defesa central absolutamente incrível 👏
Português
0
0
5
146
André
André@atmcarmo·
Que vitória do Porto. Que vitória. Vamos 💙
Português
0
0
14
212
André
André@atmcarmo·
Braga com 2 vermelhos perdoados aos 34 minutos de jogo. O VAR está avariado?
GIF
Português
2
29
240
5.5K