
CodeByMDB.eth 💜 (.lens)
15.5K posts

CodeByMDB.eth 💜 (.lens)
@codebymdb
Developer, Founder @rhythmandbiz @0xPolygon guild mage putting music onchain w/ @beatstacksonbtc. Alphaeigener @eigenlayer, #BITAmbassador


all you nerds hyperventilating about your claude code config would be gobsmacked by the sophistication devin has had for months. cc is catching up but still relatively unserious


Happy 30th anniversary to the Internet Archive (launched on May 10, 1996). A staggering piece of history and technology that must be preserved.



SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.


Elon Musk’s DOGE “blatantly used” race, gender and other protected characteristics to execute the largest mass termination of federal grants in the history of the National Endowment for the Humanities, a federal judge ruled on Thursday. abcnews.link/kfJxWVn











