
Pham Tai Tue
363 posts

Pham Tai Tue
@tuedenn
Hit and Miss, Seek and Hide. You and I, remember that: “Not all treasure’s silver and gold, mate.” I’m a man of my word, and my words are my own!






If you’re looking for ways to reduce the risk from compromised #NPM packages, here’s a solid post from Hacker News. I contains a few practical steps to harden your setup: - Use pnpm. It’s faster, takes less space, and blocks post-install scripts by default. Most of them are useless or shady anyway. - Set minimumReleaseAge to delay fresh packages. In recent attacks, that delay alone would’ve been enough to avoid pulling malicious versions. - On Linux, wrap your package manager in bubblewrap. Keeps the junk from touching sensitive files like ~/.ssh No tools to buy. No pipelines to rebuild. Just small changes that help. Hacker News post: news.ycombinator.com/item?id=452743… Config: #minimumreleaseage" target="_blank" rel="nofollow noopener">pnpm.io/settings#minim…



AI writes your code in 30 seconds. You spend 3 hours debugging what it wrote. You could have written it yourself in 45 minutes. But that would require thinking and we don't do that anymore apparently.



















0apt ransomware is a potential scam op. 💀 We analyzed 230+ victim claims, the majority were fake, with no samples or proof, and they even report companies that don’t exist. First alert by @alvieriD. Now claiming hits on 4 major UAE entities using manufactured screenshots. AI hype fuels the noise.









