Araya

42.7K posts

Araya

Araya

@kiunye_

WooCommerce Engineer | Elixir & Ruby on Rails guy

Katılım Ocak 2010
467 Takip Edilen880 Takipçiler
Araya retweetledi
JNS
JNS@_devJNS·
ZXX
20
145
2K
72.8K
Araya retweetledi
John Doe
John Doe@StanleyMasinde_·
People need to start getting paid for taking interviews. The screening call is free. Any extra round will be charged at an hourly rate. Make it 6 rounds, I make a days wage.
English
4
15
58
2.4K
Araya retweetledi
John Doe
John Doe@StanleyMasinde_·
Okay, guys, POS mmeunda mingi sana. Share yours or your favourite and your unique value proposition. I feel like we should either create partnerships or venture into other stuff.
English
18
25
152
13.6K
Araya retweetledi
Ayaan 🐧
Ayaan 🐧@twtayaan·
DevOps expectations vs DevOps reality 😐
Ayaan 🐧 tweet media
English
5
79
711
14.7K
Araya retweetledi
Jessy_szn💕
Jessy_szn💕@Astro_jessie·
Realizing corporate life requires an ass licking skill set I was not born with
English
84
6.5K
41.8K
1.2M
Araya retweetledi
JNS
JNS@_devJNS·
ZXX
213
1.3K
12.9K
542.8K
Araya retweetledi
Hon. Japheth Ouma
Hon. Japheth Ouma@JaphethOtieno01·
This guy from Tigania East forgot this was a Tutam meeting and said what was in his heart. He was chased away after being given ngumi moja safi. 😀
English
82
490
1.8K
104.1K
Araya retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
International Cyber Digest@IntCyberDigest

‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.

English
130
748
4K
2.6M
Araya retweetledi
Dmitrii Kovanikov
Dmitrii Kovanikov@ChShersh·
Once again I’m reminded how lucky we’re in C++ not to have a package manager and therefore no supply-chain attacks
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
67
51
1.4K
143.2K
Araya retweetledi
Low Level
Low Level@LowLevelTweets·
nah im just not gonna run npm install anymore
English
191
435
8.7K
383K
Araya retweetledi
Araya retweetledi
vx-underground
vx-underground@vxunderground·
TanStack
vx-underground tweet media
Svenska
22
163
1.8K
31.9K
Araya retweetledi
TANSTACK
TANSTACK@tan_stack·
SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.
English
135
984
3.8K
3.9M
Araya retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
International Cyber Digest tweet media
English
138
957
6.4K
1.5M
Araya retweetledi
NearestCommit
NearestCommit@NearestCommit·
Average AI Bro take be like
NearestCommit tweet media
English
181
913
30.8K
1.2M
Araya retweetledi
Temujin
Temujin@harrysreup·
Got into a matatu without my headphones so I'm frying my braincells listening Maina and King'ang'i. Retard 1: "Happy mother's day kwa wanaume wako na umama" Retard 2 (co-host): *dies of laughter *Ad break *Worst song you've ever heard "Good times and great hits🔥"
English
79
1K
5.5K
116.1K
Araya retweetledi
Branko
Branko@brankopetric00·
Kubernetes is a brilliant solution to problems created by adopting Kubernetes. You had a working deployment script...
English
13
3
83
5.6K
Araya retweetledi
Sun Tzu
Sun Tzu@ItsChanzu·
Kitu Macron anaweza saidia hapo UON kwa youth engagement ni kupea vijana script ya kuteka wamama wazee 😂
Indonesia
62
982
4.9K
66.4K