frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: WeaveMind – AI Workflows with human-in-the-loop

https://weavemind.ai
2•quentin101010•2m ago•0 comments

Show HN: Seedream 5.0: free AI image generator that claims strong text rendering

https://seedream5ai.org
1•dallen97•4m ago•0 comments

A contributor trust management system based on explicit vouches

https://github.com/mitchellh/vouch
2•admp•6m ago•1 comments

Show HN: Analyzing 9 years of HN side projects that reached $500/month

2•haileyzhou•6m ago•0 comments

The Floating Dock for Developers

https://snap-dock.co
1•OsamaJaber•8m ago•0 comments

Arcan Explained – A browser for different webs

https://arcan-fe.com/2026/01/26/arcan-explained-a-browser-for-different-webs/
2•walterbell•9m ago•0 comments

We are not scared of AI, we are scared of irrelevance

https://adlrocha.substack.com/p/adlrocha-we-are-not-scared-of-ai
1•adlrocha•10m ago•0 comments

Quartz Crystals

https://www.pa3fwm.nl/technotes/tn13a.html
1•gtsnexp•12m ago•0 comments

Show HN: I built a free dictionary API to avoid API keys

https://github.com/suvankar-mitra/free-dictionary-rest-api
2•suvankar_m•14m ago•0 comments

Show HN: Kybera – Agentic Smart Wallet with AI Osint and Reputation Tracking

https://kybera.xyz
1•xipz•16m ago•0 comments

Show HN: brew changelog – find upstream changelogs for Homebrew packages

https://github.com/pavel-voronin/homebrew-changelog
1•kolpaque•20m ago•0 comments

Any chess position with 8 pieces on board and one pair of pawns has been solved

https://mastodon.online/@lichess/116029914921844500
1•baruchel•22m ago•1 comments

LLMs as Language Compilers: Lessons from Fortran for the Future of Coding

https://cyber-omelette.com/posts/the-abstraction-rises.html
2•birdculture•23m ago•0 comments

Projecting high-dimensional tensor/matrix/vect GPT–>ML

https://github.com/tambetvali/LaegnaAIHDvisualization
1•tvali•24m ago•1 comments

Show HN: Free Bank Statement Analyzer to Find Spending Leaks and Save Money

https://www.whereismymoneygo.com/
2•raleobob•28m ago•1 comments

Our Stolen Light

https://ayushgundawar.me/posts/html/our_stolen_light.html
2•gundawar•28m ago•0 comments

Matchlock: Linux-based sandboxing for AI agents

https://github.com/jingkaihe/matchlock
1•jingkai_he•31m ago•0 comments

Show HN: A2A Protocol – Infrastructure for an Agent-to-Agent Economy

1•swimmingkiim•35m ago•1 comments

Drinking More Water Can Boost Your Energy

https://www.verywellhealth.com/can-drinking-water-boost-energy-11891522
1•wjb3•38m ago•0 comments

Proving Laderman's 3x3 Matrix Multiplication Is Locally Optimal via SMT Solvers

https://zenodo.org/records/18514533
1•DarenWatson•41m ago•0 comments

Fire may have altered human DNA

https://www.popsci.com/science/fire-alter-human-dna/
4•wjb3•41m ago•2 comments

"Compiled" Specs

https://deepclause.substack.com/p/compiled-specs
1•schmuhblaster•46m ago•0 comments

The Next Big Language (2007) by Steve Yegge

https://steve-yegge.blogspot.com/2007/02/next-big-language.html?2026
1•cryptoz•47m ago•0 comments

Open-Weight Models Are Getting Serious: GLM 4.7 vs. MiniMax M2.1

https://blog.kilo.ai/p/open-weight-models-are-getting-serious
4•ms7892•57m ago•0 comments

Using AI for Code Reviews: What Works, What Doesn't, and Why

https://entelligence.ai/blogs/entelligence-ai-in-cli
3•Arindam1729•57m ago•0 comments

Show HN: Solnix – an early-stage experimental programming language

https://www.solnix-lang.org/
2•maheshbhatiya•58m ago•0 comments

DoNotNotify is now Open Source

https://donotnotify.com/opensource.html
5•awaaz•59m ago•2 comments

The British Empire's Brothels

https://www.historytoday.com/archive/feature/british-empires-brothels
2•pepys•1h ago•0 comments

What rare disease AI teaches us about longitudinal health

https://myaether.live/blog/what-rare-disease-ai-teaches-us-about-longitudinal-health
2•takmak007•1h ago•0 comments

The Brand Savior Complex and the New Age of Self Censorship

https://thesocialjuice.substack.com/p/the-brand-savior-complex-and-the
2•jaskaransainiz•1h ago•0 comments
Open in hackernews

Shai Hulud launches second supply-chain attack

https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
352•birdculture•2mo ago

Comments

benzible•2mo ago
Dup https://news.ycombinator.com/item?id=46032539 [edit: not a dup!]
swsieber•2mo ago
This article has quite a bit more information though.
dang•2mo ago
Thanks—I've added this link to the toptext at https://news.ycombinator.com/item?id=46032539.
thih9•2mo ago
Not a dup, this is a different article about the same event, with different information too.
a4isms•2mo ago
Please use the word "Dup" for a resubmission of the same link and "See also" for a different submission.
neogodless•2mo ago
See also: https://news.ycombinator.com/item?id=46032539 Shai-Hulud Returns: Over 300 NPM Packages Infected (helixguard.ai)

~6 hours ago | 430 comments

dang•2mo ago
Ok, we've merged the (relevant) comments thither. Thanks!

Edit: Here's a bit of explanation for those curious. Even though the links are different, the test we use for whether to merge threads is whether they are substantially the same story vs. whether the two links will lead to substantially different discussion. In this case it's clear that it's the same discussion, so I merged them.

Since the second link has additional information, I've added it to the toptext of the original post. That way people can look at both.

QuantumNomad_•2mo ago
Typo in title. Current title of HN post says:

> SHA1-Hulud the Second Comming – Postman, Zapier, PostHog All Compromised via NPM

Should be Shai-Hulud, not SHA1-Hulud.

adzm•2mo ago
That said, the secrets are uploaded to a repo named `Sha1-Hulud: The Second Coming`
zahlman•2mo ago
Ah, I missed that detail.
zahlman•2mo ago
I don't know why you were downvoted. The actual page does not say SHA1, the attack as far as I know is not related to the SHA1 algorithm, and the name of the worm isn't intended as that sort of pun.
pezezin•2mo ago
The worm itself is posting the secrets in Github with the name Sha1-hulud: https://github.com/search?q=sha1-hulud&type=repositories
cyberpunk•2mo ago
Yikes. AWS secrets galore in the couple I decoded (double base64)...

I'm surprised github is leaving these up.

galangalalgol•2mo ago
At this point it likely helps the defenders more than those that would use them doesn't it?
meowface•2mo ago
I am guessing they don't intend to and will be removing them with urgency.
AlexandrB•2mo ago
Also "coming" only has one "m". Or is this some kind of pun?
ChrisArchitect•2mo ago
[dupe] Discussion: https://news.ycombinator.com/item?id=46032539
welder•2mo ago
Python script to check if any of your repos have the listed compromised packages in pnpm or npm lock files:

https://chatgpt.com/s/t_6924b232a8f88191a146a510c6631143

artisin•2mo ago
Worth mentioning that Bubblewrap[1] (bwrap) can remove most npm/node attack vectors or, at the very least, limit the damage from running arbitrary code during install/execution. Far from a silver bullet, and you'll want to combine it with a simple wrapper script to avoid dinking around with all its arguments, but it beats dealing with rootless Podman containers.

[1] https://github.com/containers/bubblewrap

port11•2mo ago
This looks really interesting, but it sounds like it's as complicated to setup as rootless Podman — which is to say not _that_ complicated. Anyone using this with Node or Deno successfully?
bunnybender•2mo ago
From my bookmarks (2023): https://news.ycombinator.com/item?id=36686461
port11•2mo ago
Lovely. Thank you very much!
splix•2mo ago
We made a script to avoid such situations. It checks the dependencies, just by parsing the package.json (or the lock file), checking the relevant time on npm registry, and returns error if it finds a too fresh package added.

We run it on CI for each commit/PR, and if a developer tries to commit a change that updates a JS dependency to a too recent it prevents the build from running, and so on. Basically we expect that a Supply Chain attacks on NPM would be noticed in a couple of week, and we enforce this time window to our code.

See https://github.com/emeraldpay/paranoid.js