
Drew Lustro
2.3K posts

Drew Lustro
@drewlustro
engineer, currently addicted to agents today – @gotremendous previous – @angellist, @maxrelaxco studio created Epic Pet Wars w/ @amitm




Git is just bad. Use jj, and stop complaining about concepts when the implementation is bad.

President Trump posts an AI-generated image depicting himself as Jesus on Truth Social









🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.



Code[dot]Storage A new Git provider for machines by @pierrecomputer. In Oct, Github shared they were averaging ~230 new repos per minute. Last week we hit a sustained peak of > 15,000 repos per minute for 3 hours. And in the last 30 days customers have created > 9m repos🧵


A small thank you to everyone using Claude: We’re doubling usage outside our peak hours for the next two weeks.

What gaming opinion will you defend like this?🚀













