bern 🦉
2K posts

bern 🦉
@vibern0
i build things at @gnosis_. nice and useful things for people








🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.


‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.





🌡️ Update on the CO2 bedroom saga I tried this tip by @jesper_bee We have a bathroom in the bedroom with a vent (for removing humidity after showering), so I kept the door open and vent on Anyway it worked CO2 at night peaked at 850ppm, still a bit high but almost half of before with window closed, improvement Sleep was 95% on WHOOP and gf 91% on OURA (inb4 cancelled for tracking things *omg so neurotic*) Will try window open + bathroom vent open tonight but again sound outside at night is an issue The real solution is an inward vent tube to actual bedroom though, as I think the bathroom vent is outward and doesn't get us to 400ppm CO2 by itself Nice fresh air 💨







You walked through your old high street last week. Wilko's gone. WHSmith is gone. There's a row of vape shops on one street. A few more are Turkish barbers. There's a kebab shop where the Argos used to be. Half the units have 'TO LET' in the window. The town centre your parents grew up in doesn't exist anymore.







