
Still writing blog post hopefully will post tomorrow
eric
504 posts

@codebutler
sw eng @getbasiccapital

Still writing blog post hopefully will post tomorrow

🚨 Socket detected malicious activity in newly published versions of node-ipc, an npm package with 822K weekly downloads. Affected versions: node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@12.0.1 Socket’s AI scanner flagged the malware within ~3 minutes of publication. Early analysis shows obfuscated stealer/backdoor behavior, including host fingerprinting, local file enumeration, payload wrapping, and attempted exfiltration.

🚨 We’ve confirmed the intercom-client@7.0.4 was compromised in the ongoing Mini Shai-Hulud worm attack. The npm package includes a malicious preinstall hook that downloads and executes an unverified Bun binary, then runs an 11.7 MB obfuscated payload designed to steal Kubernetes, Vault, cloud, GitHub, and CI/CD secrets. The attack closely overlaps with the SAP CAP, Cloud MTA, and lightning@2.6.2 compromises.

React Compiler: Rust edition is coming soon. We've ported the majority of the passes using AI. When the initial port finishes we'll do some updates to get the code in a state we're happy to maintain, then extensive testing and look at performance. More to come soon



I was a 10x engineer. Now I'm useless.

A New York bill would ban AI from answering questions related to several licensed professions like medicine, law, dentistry, nursing, psychology, social work, engineering, and more. The companies would be liable if the chatbots give “substantive responses” in these areas.



In 2013, when government tried mass domestic surveillance, the tech industry responded with HTTPS everywhere. In 2026:
