Jay
106 posts

Jay
@jaypopat0
Full time builder | Exploring agents | PBA Grad https://t.co/rFUdZkNJV3







SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.
















Spent 4 months and built Omi for Desktop, your life architect It sees your screen, hears your conversations and tells you what to do next It’s like having a second brain that actually pays attention Open source, local, link below




Bloom is joining YC for the Spring batch. We’re building the future of branding and marketing. The vision is for Bloom to be the “Brand Operating System” - a system that deeply understands your brand and powers everything it touches. Since launch, over 40,000 people have used Bloom to create on-brand assets. Our revenue has tripled in the past month. Thank you @koomen and @ycombinator for the support. We’re building our team in San Francisco. If you want to own massive scope and help build something huge, link below.













