deep//maker

64 posts

deep//maker banner
deep//maker

deep//maker

@deepmaker_us

Solo dev. One project. Building a world that hunts, adapts, and remembers. All from scratch.

Cincinnati, OH Entrou em Mart 2026
38 Seguindo6 Seguidores
deep//maker
deep//maker@deepmaker_us·
Day 72 • Last week, I got a functional heartrate signal in the player hud along with reworking bars. • Today, I got the heartrate signal working with actions like sprinting, jumping, being damaged, low stamina, suffering from status affects, etc. #solodev #indiedev #gamedev
GIF
English
0
0
3
39
deep//maker
deep//maker@deepmaker_us·
Day 68 • Reworked the hotbar's positioning, design, and selection. • Added cursor hover effect. • Removed a panel from the inventory and added more buttons. • Fixed Bug: Discovered a duplication bug. • Noted Bug on To-Do: swapping items sometimes deletes the item being swapped to; only from hotbar to inventory. Tomorrow's another day! #indiegame #indiedev #solodev
GIF
English
0
0
0
23
deep//maker
deep//maker@deepmaker_us·
Day 67 I've been hammering away at getting this menu functional and aesthetically sound with my vision. Fixed a few bugs, rewrote the inventory script twice, and wrote a lot of shaders. CRT + Phosphor + Cathode Modulation! #gamedev #solodev #godot
GIF
English
0
0
2
82
Muhammad Ayan
Muhammad Ayan@socialwithaayan·
🚨 BREAKING: Someone turned Claude Code into a full game development studio with 48 AI agents. Claude Code Game Studios mirrors an actual studio hierarchy inside your terminal: → 48 specialized AI agents each with a distinct role → Art Director, Level Designer, QA Lead, Sound Designer and more → 36 workflow skills covering the full game development lifecycle → A coordination system that manages agents like a real studio pipeline → Build complete games with AI agents handling every department 3,000 stars and rising fast. 100% free and open source.
Muhammad Ayan tweet media
English
143
190
2K
306.5K
deep//maker
deep//maker@deepmaker_us·
@jamesrcole @socialwithaayan "Idiots trying to us AI as a means to produce instead of a tool to aid again." AI is a great tool. OP is pointing out the use of generative AI to replace an entire studio of humans; AI is being used as THE means to produce something, not as a tool in that regard.
English
1
0
1
79
James Cole
James Cole@jamesrcole·
How is this not a tool to aid? Also, this is like version 0.001 of such a tool. Imagine what version 5 of it, 5 years from now, will be like. It’ll allow people to test out ideas quickly. It’ll allow individual creators or very small teams to produce games that previously wouldn’t have been possible for teams of that size.
English
4
0
1
153
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
297
2.2K
10.9K
2.7M
deep//maker
deep//maker@deepmaker_us·
Day 56 I spent the day reworking the inventory menu in attempt to style it & make it work with what I had in mind. While it started to go in the direction I wanted, the 2D canvas mapping is offset since the effect is visual only ('cuz shader). Tomorrow is another day. #gamedev #indiedev #GodotEngine
deep//maker tweet media
English
0
0
5
95
deep//maker
deep//maker@deepmaker_us·
@Pirat_Nation Haven't seen an ad on Youtube since I installed @brave on the desktop. 🤷🏻‍♂️
English
0
0
0
84
Pirat_Nation 🔴
Pirat_Nation 🔴@Pirat_Nation·
Linus Tech Tips called out YouTube's new 30-second unskippable ads on the TV app, asking "When will it be enough? Are we just going to go all the way back to cable TV with three-minute ad breaks? Can we not?"
Pirat_Nation 🔴 tweet mediaPirat_Nation 🔴 tweet media
English
255
377
6K
131.8K
Krusty
Krusty@crusty_ol·
@Matt_Pinner There is a peace in the world before all you other fvckers get up and ruin it.
English
42
13
440
4.9K
JuLieMine
JuLieMine@juliemine_rus·
@LegendaryNIK @DaveOshry fair, fair, didnt know godot was free! steam is the only option for people like me, so id probably also go there for getting software. though maybe theyre using steam to track their hours in it, since steam does tracks that?
English
1
0
2
1.3K
Dave NewBlood
Dave NewBlood@DaveOshry·
Goddam Indonesia HATES Godot Engine
Dave NewBlood tweet mediaDave NewBlood tweet media
Indonesia
91
443
8.5K
428.1K
Aryan
Aryan@justbyte_·
Tell us about your programming skills using emojis only.
English
74
2
49
4.9K
Arne the Derptato
Arne the Derptato@DerpCrossing·
@deepmaker_us @PickMon_UK Dude is talking shit about Nintendo... despite the fact that he's trying to sell the game on the Switch... so he's trying to get the best of both worlds by censoring the name.
English
2
1
4
176