
ɐsɹǝʌǝɔıʌ
137 posts

ɐsɹǝʌǝɔıʌ
@coffeeshopperr
Staff ML Engineer @ Upwork. Health Informatics Research @ Karolinska Institute, ex-MIT and med student as a hobby. building cool side-projects.









🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

This week in security: - LiteLLM, backdoored release exfiltrating secrets - Axios, supply chain malware via dependency - Railway, CDN caching leaked user data - OpenAI Codex, command injection via GitHub branch names - Mercor 1TB data leak - Delve, data leak + compliance risk infra is the attack surface now

Claude code source code has been leaked via a map file in their npm registry! Code: …a8527898604c1bbb12468b1581d95e.r2.dev/src.zip

pergunta genuína: se a pessoa tem 10k+ inscritos em alguma rede social, não compensa mais pra ela investir no próprio tráfego pago e crescer ao invés de fazer um estágio por um salário mínimo? Se ela tá em começo de carreira e já conseguiu 10k+ audiência, provavelmente algum diferencial ela tem que vale mais de 1600 reais...

PROGRAMA DE ESTÁGIO pretendo contratar 10 estagiários ao longo de 2026, começando esse mês o programa vai durar 3 meses requisitos: > saber usar claude code > +10k inscritos em alguma rede social > ter uma PJ e conseguir receber em € > estar okay em aparecer no canal benefícios: > um salário mínimo (R$1621) > acesso ao Stupid Button Club > comissão + bônus > Gift Claude Max carga horária obrigatória: ZERO mandar e-mail pro e-mail do perssua

Claude code source code has been leaked via a map file in their npm registry! Code: …a8527898604c1bbb12468b1581d95e.r2.dev/src.zip















