Daniel
5.6K posts

Daniel
@itsdevdaniel
⚫️ Bootstrapped founder building apps ⚫️ Sold a Startup ⚫️ Senior Software Developer ⚫️ Building Shopify, Wix & iOS apps.

UPDATE: So far we've identified 639 compromised npm package versions across 323 unique packages in tonight’s Mini Shai-Hulud wave. That includes 558 versions across 279 unique @antv packages. Most were detected within ~6 minutes of publication. socket.dev/blog/antv-pack…

Spotify has CRASHED due to the launch of Drake's three new albums.




@ShopifyDevs does this seem right to you? A merchant searched for "size chart" and not a single size chart ad showed up in the ads. On specific search pages, there should be a relevance factor to the search. This has been a recent change too. The 4 largest of us, use to all show up in the ads.

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

Just got drained or hacked for more than 200k. Sick to my stomach This is the wallet where the money went: 0xF7cFFC27732a5C9c4E2D592F3E33435F8dDb019A Any help to track the money would be appreciated








