farzaan

138 posts

farzaan banner
farzaan

farzaan

@justfarzaan

Building and Shipping | https://t.co/39XFRwWhYg

Katılım Şubat 2025
136 Takip Edilen13 Takipçiler
Sabitlenmiş Tweet
farzaan
farzaan@justfarzaan·
What started as a small feature back in April, turned into a full-fledged app today. I've truly enjoyed building this product and sharing it with this amazing community. There's definitely more to come 🥂
farzaan tweet media
farzaan@justfarzaan

Finally launched KnowMyDocs🚀 I was tired of AI that lose context, hallucinate, and hide what they’re doing. So I built a tool to chat with documents - now with transparency, and control. Create projects, have advanced controls and get answers instantly. knowmydocs.com

English
0
0
2
219
farzaan retweetledi
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just hijacked the npm account of axios's lead maintainer, swapped his email to a burner ProtonMail, and published poisoned versions of a package that 100 million developers install every week. The attacker didn't touch the axios source code. They added one line to the dependency list: plain-crypto-js@4.2.1, a package that didn't exist 24 hours ago. That single line triggers a postinstall script the second npm processes the package. You don't import it. You don't call it. It fires on install. The staging was surgical. 18 hours before the attack, they published a clean version of plain-crypto-js to build publishing history on npm so automated scanners wouldn't flag a brand new account. Then at 23:59 UTC on March 30 they pushed the real payload. Both axios@1.14.1 and axios@0.30.4 went live within 39 minutes of each other. The payload is a three-platform RAT. macOS gets a binary disguised under Apple's cache naming conventions. Windows gets a hidden PowerShell script with execution policy bypassed. Linux gets a Python RAT dropped into /tmp. After deployment, the dropper deletes itself, strips the postinstall hook from package.json, and replaces it with a clean stub. A developer inspecting node_modules after infection finds nothing. Here's how they got in. Every legitimate axios release is published through GitHub Actions using npm's OIDC Trusted Publisher mechanism, cryptographically tied to a verified workflow. This release broke that pattern completely. Published manually via a stolen npm access token. No OIDC binding. No GitHub commit. No tag. The entire CI/CD security pipeline was irrelevant because the attacker never used it. Socket's automated detection flagged the malicious package in six minutes. Six minutes is fast. But npm install runs in seconds. Every CI/CD pipeline, every developer machine, every production deploy that pulled the latest axios in that window is potentially running a remote access trojan right now. The companies shipping code the fastest have the least visibility into what's underneath it.
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
20
66
417
138.9K
farzaan
farzaan@justfarzaan·
GIF
vx-underground@vxunderground

There is a project on GitHub called Axios. Axios is extremely popular. It is used by millions upon millions of applications. Axios is a programming library that helps your JavaScript code make HTTP/S requests (communicate with websites). In simple terms, if you're a programmer doing something with JavaScript, and want to do stuff that communicates with a website in literally any capacity, people heavily recommend using Axios due to its simplicity. Using Axios you don't have to reinvent the wheel and do a bunch of work. All you need to do is import Axios into your code and you're off to the races. Someone (currently unknown) compromised Axios (currently unknown how) to deliver malware to people. When someone updates or installs Axios, Axios itself contains malware. What the malware does is (currently) unknown, but it is being reversed engineered by probably every malware analyst on the planet at this moment. In a few hours more details will emerge. Information is being exchanged in real time on social media and private communication platforms as I write this. Due to the size and popularity of Axios, it is unknown how many are impacted, it could be millions, it could be thousands, or if we're lucky, only hundreds of people or organizations will be impacted. If this is absolute worst case scenario, millions of organizations across the planet have been infected with malware which (currently) we do not understand. However, the likelihood of this is low. It appears Axios being compromised was detected quickly, potentially within minutes (or hours) of it being compromised to deliver malware. Additionally, the likelihood of every single Axios user updating Axios as soon as it was compromised to deliver malware is astronomically low. It is basically zero. The impact from Axios being compromised is devastating, the fallout from this will be a massive headache. This is unironically a malware nuclear missile and will likely be studied in the future.

ZXX
0
0
0
38
farzaan
farzaan@justfarzaan·
@RealAnkush Another guess is a modern skills-based alternative to college. Project-based learning + guaranteed pathways to jobs. Sustainable model so it funds itself long term.
English
0
0
0
13
farzaan
farzaan@justfarzaan·
@RealAnkush Feels like you are building a serious job-first tech ecosystem. Not just teaching coding but making people work on real projects and directly hiring from there. That would actually create real employment at scale.
English
0
0
0
14
Tanay Kothari
Tanay Kothari@tankots·
We will give you a Porsche GT 3 RS if you can type faster than @WisprFlow can dictate. Last week, we challenged 5 users to get Wispr to make a mistake. 3.5 Million people watched the challenge and wanted in. Now we're opening the challenge to everyone. Comment "Porsche" and you'll get a link to participate. Prizes apart from the Porsche: 1. Lifetime Wispr Flow Pro membership 2. 6 months of Flow Pro if you QRT with your score 3. Flow Desktop Mic 4. Exclusive Flow Merch
Tanay Kothari@tankots

We offered 5 people a Porsche 911 GT3 RS if they could get @WisprFlow to make a mistake It's the fastest and most accurate AI voice dictation app that's 3x more accurate than ChatGPT, Claude, or Siri. Today, we’re finally launching on Android. Download now: play.google.com/store/apps/det… As a part of the launch, we’re giving away 6 months of Wispr Flow Pro for free. Like, retweet and comment ‘Wispr Flow’ to get it. Enjoy. — Written with Wispr Flow

English
1.3K
161
1.3K
988.7K
farzaan
farzaan@justfarzaan·
@primusibi It was too short. Barely 6hrs of playtime.
English
0
0
0
19
IBI
IBI@primusibi·
Remind me Why do People hate this game? Personally it’s a solid 8/10 from me
IBI tweet media
English
292
106
3.6K
398.3K
farzaan
farzaan@justfarzaan·
@FarzaTV 🔥 sounds interesting!
English
0
0
1
64
Farza 🇵🇰🇺🇸
Farza 🇵🇰🇺🇸@FarzaTV·
I'm going to teach a group of people how to build their first app with AI this week using Codex. I'll do a live tutorial, then we'll all cowork + build. if you don't have an idea to work on, dw I'll help with that too. If you wanna join the call, reply with your fav emoji :-)
English
1.7K
158
3K
354.3K
Alessandro
Alessandro@alessssndro16·
@juliandceu @iREUS_SA "I guess" It's not any official source. I said Superman / Green Arrow because 1. In DcKo it's shown Green Arrow with the others 2. Hawkman will fight Superman, and he killed Oliver Queen. GL / MM are just the ones who left, because Wally is not part of the team shown in DcKo
Alessandro tweet media
English
2
0
2
247
REUS | رويس
REUS | رويس@iREUS_SA·
The Absolute Universe will have its first event in Q4 of this year!
REUS | رويس tweet media
English
9
172
2.6K
39.1K
Asish Kumar
Asish Kumar@asishcodes·
Cursor is now a money-making scam. Their $20 plan is pure shit.
English
161
18
1.1K
157.8K
farzaan
farzaan@justfarzaan·
@viditchess Have you deployed any vibe-coded application that you've built?
English
0
0
2
11.3K
Vidit Gujrathi
Vidit Gujrathi@viditchess·
Have some time on my hands. Let’s do an AMA. Shoot your questions. :)
English
190
2
282
33.6K
farzaan
farzaan@justfarzaan·
@Aswin_polymath @mehulmpt They say it can. I have tried multiple times but it always fails to make even the simplest ones. It hallucinates and thinks it has created a job. I later had to manually add the job in the file and then it started working.
English
1
0
4
601
Mehul Mohan
Mehul Mohan@mehulmpt·
yeah clawdbot is great
Mehul Mohan tweet media
English
86
20
4.1K
346.9K
farzaan
farzaan@justfarzaan·
@gregisenberg Guilty, Is there any saas that organizes them for you?
English
0
0
0
9
GREG ISENBERG
GREG ISENBERG@gregisenberg·
people just bookmark stuff on X with zero real intention of every checking those said bookmarks
English
929
42
1.9K
144.7K
Epic Jimmy
Epic Jimmy@Epic_Jimmy·
Using Blender for the first time
Epic Jimmy tweet media
English
81
3.1K
44.2K
1.9M
Umar Mirza
Umar Mirza@iumarmirza·
I’ve been working as a freelancer for more than two years now, and over time the only tool or platform I’ve seen that can genuinely change your life is @framer. Recently I gave advice to a designer who was struggling to get accepted as a Framer expert. After listening to my advice she applied and got approved the next day. You might think becoming an official Framer expert is nothing more than an achievement, but no. It is the door to unlocking opportunities that can make you thousands of dollars. I made my first money with Framer after 52 days of starting, and guess what? I started getting enquiries only after I got my Framer expert badge and profile. It has been three months since I became a Framer expert, and I have worked with more than 10 clients and made a good amount of money. If you are into Framer and not applying for their expert program, you are missing out on a lot of opportunities. Comment "Advice" and I will send you that advice in your DMs. PS: Make sure you follow me so I can DM you :)
Umar Mirza tweet media
English
348
11
499
45K
Jordi Hays
Jordi Hays@jordihays·
Rage Baiting is for Losers Yesterday, YC announced Chad IDE aka “the brainrot code editor.” Chad is an AI code editor that allows you to gamble, watch TikTok, and use dating apps while working on coding tasks. Their launch rightfully got a lot of attention. On one hand it’s funny. On the other hand, what are we doing here and why does this belong on the official YC account? To understand Chad IDE, Cluely, Icon, Friend, and the new class of Gen Z startups, you have to understand the online environment these founders grew up in. If you grew up on the internet and studied how and why certain people would regularly go viral, you know that making people mad has and always will be a highly effective way to get attention. The feedback loop is simple: 1) make something (product or ad) that makes people angry; 2) people comment/ share/ dunk; 3) because feeds are optimized to show posts with high engagement the most, you get more reach. Rage baiting for commercial purposes was pioneered by course bros. People like Tai Lopez realized that making the masses mad was an effective way to drive course sales. They could flaunt Lamborghinis, make a bunch of people angry, and as long as a handful of people found their way into their course, it was a viable, repeatable strategy. Historically on X, rage baiting was a marketing strategy, not a product strategy. Accounts like @sweatystartup frequently post things to get an angry reaction and subsequent reach, but behind the scenes he's always been running a normal commercial real estate fund. In 2025, rage baiting has become a product strategy. Cluely started as an app for cheating on coding interviews. Chad IDE’s only known differentiation from the other hundred AI native IDEs is that you can gamble and swipe on dating apps in it. The rage bait is sitting at the product level now. It’s becoming clear that while rage bait might occasionally work as a marketing strategy, it really should not be employed as a product strategy. Running a successful VC-backed company requires you to build a coalition of people that want to see you win. Getting media, investors, talent, and customers on your side is not an easy task. Rage baiting (whether at the marketing level or product level) is the most effective way to get people (who could be potential investors, customers, or team members) to actively pray for your downfall. YC has long provided some of the most durable, high quality, generalizable advice for startups and I believe it has had a tremendously positive impact on the companies that go through YC and even those that don’t. Launch now, make something people want, do things that don’t scale, ignore your competitors, etc. As someone who believes that YC is one of the most important and influential institutions in tech, I believe it might be time to include this in their list of essential startup advice: “Rage baiting is for losers.”
English
294
199
3.7K
1.5M
VEED | AI Video Creation
VEED | AI Video Creation@veedstudio·
Minimax Hailuo 2.3 is LIVE on VEED first 💥 Best VFX + motion physics in AI video is here! • realistic micro-expressions • cinematic details • insane animation 🚨Free 500 Credits in DM for first 200 users, who: - Retweet - Comment (only for next 24 hours)
English
335
291
498
100.5K
LTX Studio
LTX Studio@LTXStudio·
🚨 800 FREE CREDITS — 24 HOURS ONLY We just launched LTX-2, our most powerful video model yet. High-res. Fast. Cinematic. Native lip-sync. Follow + RT this post to get 800 credits sent to your DMs. Plus: All LTX-2 generations are 50% off.
English
586
1.1K
1.2K
161.1K
farzaan
farzaan@justfarzaan·
@p1njc70r Do you get the same result if the prompt is injected at the end or in the middle of the doc?
English
0
0
0
102
farzaan retweetledi
Irfan Ali
Irfan Ali@irfannnnali·
As part of @theresidency's Delta II, @FarhanSeliya and I are thrilled to introduce CurioPod! We're building the next-gen learning ecosystem to reimagine screen time for your child’s early development. Parents, this one's for you, stay tuned!
Irfan Ali tweet media
English
1
1
2
202