frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Malicious NPM Package Hides Pulsar .NET Malware Inside PNG Images

https://www.veracode.com/blog/malicious-npm-package-hiding-in-plain-pixels/
2•SamHoustonCM•1h ago

Comments

SamHoustonCM•1h ago
>We recently came across a suspicious NPM package called `buildrunner-dev`. The package is deceptively simple, containing a package.json with a postinstall hook pointed at an `init.js` file, but that’s where things got interesting.

>The postinstall script was triggered upon package installation and dropped a batch file called `packageloader.bat`. At first glance it looked like pure noise due to thousands of characters that appear to be gibberish; nature-themed REM comments, and variable names that read like a cat walked across someone’s keyboard. But as we started peeling back layer after layer of obfuscation, we uncovered a remarkably well-engineered attack chain that hides its true payloads inside the RGB pixel values of PNG images hosted on a free image service.

Show HN: Remote Coding Agent

https://github.com/tacogips/QraftBox
1•tacogips•12s ago•0 comments

Deaths in Ice Custody Texas

https://www.texastribune.org/2026/02/19/ice-detention-deaths-texas-east-montana-dilley-campos/
1•marysminefnuf•44s ago•0 comments

Claude Code in the cloud as an API (persistent workspace and scheduled jobs)

https://computer-agents.com
1•janlucasandmann•3m ago•1 comments

Beyond Slop – Why generative AI is stuck on content production, not expression

https://www.joelsimon.net/beyond-slop
2•joelS•3m ago•0 comments

Show HN: Ghostty-based terminal with vertical tabs and notifications

https://github.com/manaflow-ai/cmux
3•lawrencechen•5m ago•0 comments

Show HN: YAML SSH Task Runner

https://github.com/mikemasam/nyatictl
2•mikemasam•6m ago•0 comments

Show HN: StillOnAir – Turn YouTube into programmable, linear TV for free

https://www.stillonair.com/
2•nanamichael•6m ago•0 comments

In contrast with Trump's America, Europe's 100 gigawatt clean energy hub

https://www.cnn.com/2026/02/19/climate/trump-wind-europe-clean-energy-independence
3•asplake•6m ago•1 comments

ASCIIQuarium

https://robobunny.com/projects/asciiquarium/html/
1•threekindwords•7m ago•0 comments

Canada If Day, WW2, when "German" troops invaded Winnipeg

https://bsky.app/profile/cdnhistoryehx.bsky.social/post/3mf7y6sjumi2q
1•vinnyglennon•8m ago•0 comments

Cortex 1.6: Learning from the Way Things Unfold

https://sereact.ai/posts/cortex-1-6
1•pancakenetwork•8m ago•0 comments

Show HN: Skicamslive.com

https://skicamslive.com
1•mcoliver•8m ago•0 comments

Building an Agent SaaS with Cloudflare Containers

https://alec.is/posts/building-an-agent-saas-with-cloudflare-containers/
1•arm32•9m ago•0 comments

Show HN: Fn-p to Picture-in-Picture any macOS window

https://lowtechguys.com/pipiri/
1•alin23•10m ago•0 comments

Weather Intelligence for Smarter Sailing

https://incusgrid.com
1•cburgdorf•10m ago•0 comments

Taalas Hardcore Llama – the fastest inference on the planet

https://chatjimmy.ai
1•ljubisa_bajic•11m ago•1 comments

Apple Watch or Don't Bother

https://fireborn.mataroa.blog/blog/apple-watch-or-dont-bother/
1•samtheDamned•14m ago•0 comments

A psychedelic medicine performs well against depression

https://www.economist.com/science-and-technology/2026/02/19/a-psychedelic-medicine-performs-well-...
2•vinni2•14m ago•0 comments

The Beige Plague

https://journal.erratalabs.org/the-beige-plague
1•mldev_exe•14m ago•0 comments

Show HN: Receiver – Internet radio for GNOME with 30K pre-verified stations

https://github.com/meehow/receiver
1•meehow•14m ago•0 comments

Show HN: Hi.new – DMs for agents (open-source)

https://www.hi.new/
2•elieskilled•15m ago•0 comments

Ask HN: An approachable book on programming concepts/computer basics for a teen?

1•jamesgill•16m ago•2 comments

Malaysian Farmers Made a Fortune on Durian. Now It Is Piling Up

https://www.nytimes.com/2026/02/10/world/asia/durian-malaysia-china-demand.html
3•bookofjoe•16m ago•1 comments

'You can't just remove the cloud': US sprinting's reckoning before LA 2028

https://www.theguardian.com/sport/2026/jan/23/marvin-bracy-williams-doping-us-sprinting-paranoia
1•PaulHoule•17m ago•0 comments

Conductor removing support for Claude subscription authentication

https://twitter.com/charlieholtz/status/2024585923619590497
1•jrsj•18m ago•0 comments

A review of tumor-treating electric fields (TTFields): clinical advancements

https://pmc.ncbi.nlm.nih.gov/articles/PMC10476910/
1•CGMthrowaway•19m ago•0 comments

What's next for Chinese open-source AI

https://www.technologyreview.com/2026/02/12/1132811/whats-next-for-chinese-open-source-ai/
1•calcifer•23m ago•0 comments

Show HN: CursorLens – Open-source screen recorder/editor for product demos

https://github.com/blueberrycongee/CursorLens
1•blueberrycongee•23m ago•0 comments

Ask HN: What makes AI agent runtime logs defensible under adversarial audit?

1•catarina_eng•23m ago•0 comments

Show HN: Auto-scrolling for WhatsApp group chats

https://github.com/avremel/whatsapp-groupchats-extension
1•avremel•26m ago•0 comments