Nick Ang
6.5K posts

Nick Ang
@nickang
ex-shopify sr eng (10 yrs) → now shipping products solo 👨💻 I build Album and document everything here & on slow riches substack (299 subs)

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

Back on @obsdmd as my second brain and I pointed Claude Cowork at my vault. Now it generates a daily digest every morning with all my project statuses. I open my laptop and immediately know where everything stands. Love it!


nothing like mornings in Southern Europe!






@ThePrimeagen Black Mirror, S2E1

#3 - Album landing page (empathetic intro copy) - intro copy empathises with core problem - sub copy explains what the product does - picked up @robhope's landing page hot tips ebook (so far, worth it)







