Kjetil H
52.3K posts

Kjetil H
@kjetilh_
Developer who loves sports (snooker, darts, disc golf, tennis). Founder and developer of @FantasySnooker_. Currently working in tech in the public sector

As it stands, "The Kritta Kritas" (Kratta Krita) leads by 123 points over "snooker I hardly knew'er" (crazyal). However, all of the The Kritta Kritas' players are knocked out which means he can only wait, see and hope that nobody passes him.






🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.



We believe we have resolved a significant performance issue affecting mainly non-European users. For about 1 month we have offered functions in non-European regions, and traffic to those caused errors and timeouts. It has been rolled back. Please let us know if you have issues.



