sonofmagic
449 posts

sonofmagic
@sonofmagic95
https://t.co/4XR2dVEdb3 | https://t.co/bnslXARDQs | npx sonofmagic@latest
China Katılım Haziran 2023
276 Takip Edilen1K Takipçiler
sonofmagic retweetledi

公司里搞政治斗争,还是非常适合
毛选.skill
github.com/leezythu/maoxu…
防止掉入别人的陷阱,找出破局之道。
中文
sonofmagic retweetledi

🚀Rolldown 1.0 is here!🚀
Rust-based high-performance JavaScript bundler.
🏎️ Runs at native speed that’s 10~30x faster than Rollup
🤝 Compatible with existing Rollup & Vite plugins
⚡The underlying bunder for Vite 8
After 2 years, Rolldown is officially stable and has 20+M weekly downloads. Companies like Framer & PLAID are already using Rolldown in production.
Thank you to every contributor, user, and team that helped us get here.

English

三件事
1. 好消息:今天收了6万
2. 坏消息:都在公账,我一个月工资5000😭
3. 第二次一个人吃一顿100块的饭

9YearFish@9yearfish
奢侈了一吧,第一次一个人吃了一顿 100 块的饭。
中文
sonofmagic retweetledi

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English














