frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

NPM install is stealing your passwords – I built a tool to catch it

https://westbayberry.com/product
3•ComCat•1h ago

Comments

ComCat•1h ago
I spent months studying how malicious npm packages actually work. Most of them do the same thing eg run a preinstall script, read your .env and credentials, and send them to a remote server. All before your app starts.

npm install will run this code automatically. No prompt, no warning.

I built Dependency Guardian a behavioral analysis engine that scans packages for malicious patterns before they touch your system.

it has: - 26 detectors (shell execution, credential theft, exfiltration, obfuscation, time bombs) - 53 cross-signal amplifiers that correlate findings across detectors - ~2,900 tests across 76 test files - Benchmarked against 11,356 real packages at 99.95% precision

It would have caught Shai-Hulud, the Chalk/Debug hijack, and the S1ngularity campaign.

Snyk, Dependabot, and npm audit all missed these because they rely on CVE databases. If there's no CVE filed yet, they're blind. Dependency Guardian reads the actual code.

curious if anyone here has been exposed/experiences to supply chain attacks and how they handled them

'AlphaFold 4' – scientists marvel at DeepMind drug spin-off's exclusive new AI

https://www.scientificamerican.com/article/an-alphafold-4-scientists-marvel-at-deepmind-drug-spin...
1•helloplanets•27s ago•0 comments

AI Isn't People

https://www.todayintabs.com/p/a-i-isn-t-people
1•HotGarbage•59s ago•0 comments

Who Wins When Everyone's Writing Code?

https://predictabledialogs.com/learn/openclaw/future-of-software
2•jaikant•16m ago•3 comments

Taiwan's PSMC Joins Intel, SoftBank's ZAM alternative to HBM AI Memory

https://www.trendforce.com/news/2026/02/23/news-psmc-joins-intel-softbanks-zam-initiative-to-manu...
1•walterbell•16m ago•0 comments

Show HN: Build Your Own CLI Coding Agent in Python

https://github.com/primaprashant/alduin
1•primaprashant•16m ago•1 comments

Rust Debugging Survey 2026

https://blog.rust-lang.org/2026/02/23/rust-debugging-survey-2026/
2•umairnadeem123•18m ago•0 comments

Machine-Generated, Machine-Checked Proofs for a Verified Compiler

https://arxiv.org/abs/2602.20082
1•umairnadeem123•18m ago•0 comments

Machine gun set up close to the University of Tehran

https://www.iranintl.com/en/202602234502
2•ukblewis•18m ago•0 comments

Show HN: Describe a workflow in plain English and builds the multi-agent system

https://www.phinite.ai/
2•PhiniteAI•21m ago•3 comments

Cassandra Complex

https://en.wikipedia.org/wiki/Cassandra_(metaphor)
2•sans_souse•22m ago•0 comments

How to Organize Safely in the Age of Surveillance

https://www.wired.com/story/how-to-organize-safely-in-the-age-of-surveillance/
1•jbegley•23m ago•0 comments

Colt – Describe a browser task in English, get a Playwright script

1•Vipul_Sharma_69•25m ago•0 comments

Anthropic misanthropic toward China's AI labs

https://www.theregister.com/2026/02/24/anthropic_misanthropic_chinese_ai_labs/
1•abdelhousni•27m ago•1 comments

Show HN: Memctl.com: Open-source shared memory infrastructure for coding agents

1•meszmate•32m ago•0 comments

The Looming Taiwan Chip Disaster That Silicon Valley Has Long Ignored

https://www.nytimes.com/2026/02/24/technology/taiwan-china-chips-silicon-valley-tsmc.html
5•blatherard•33m ago•1 comments

Workaholic open source developers need to take breaks

https://www.theregister.com/2026/02/23/open_source_devs_column/
2•abdelhousni•34m ago•0 comments

Show HN: enveil – hide your .env secrets from prAIng eyes

https://github.com/GreatScott/enveil
2•parkaboy•36m ago•1 comments

Huntarr – Your passwords and your ARR stack's API keys are exposed to anyone

https://old.reddit.com/r/selfhosted/comments/1rckopd/huntarr_your_passwords_and_your_entire_arr_s...
1•donutshop•36m ago•0 comments

Why I Hate Anthropic and You Should Too

https://danielmiessler.com/blog/why-you-should-hate-anthropic
3•curmudgeon22•42m ago•0 comments

Show HN: L88 – A Local RAG System on 8GB VRAM (Need Architecture Feedback)

1•adithyadrdo•43m ago•0 comments

Compiler Education Deserves a Revolution

https://thunderseethe.dev/posts/compiler-education-deserves-a-revoluation/
2•azhenley•46m ago•1 comments

Torvalds Drops Old Linux Kconfig Option to Address Tiresome Kernel Log Spam

https://www.phoronix.com/news/Torvalds-Unseeded-Random
2•voxadam•47m ago•0 comments

FDA approves swallowable weight-loss balloon as alternative to GLP-1 drugs

https://www.businesswire.com/news/home/20260223930098/en/Allurion-Receives-U.S.-FDA-Approval
3•sizzle•47m ago•0 comments

The Mind Illuminated [pdf]

https://ia803200.us.archive.org/view_archive.php?archive=/26/items/ebook-buddhism-2/EBOOK%20BUDDH...
2•andsoitis•47m ago•1 comments

From ASPLOS to Orbit: Unikernels Twelve Years Later

https://gazagnaire.org/blog/2026-02-23-asplos-unikernels.html
1•matt_d•48m ago•1 comments

DPDP and AIF Operations: Investor Data Compliance Guide 2026

https://taghash.io/blog/dpdp-and-aif-operations-investor-data-compliance-guide-2026/
1•koolhead17•50m ago•0 comments

Show HN: ClinTrialFinder –AI-powered clinical trial matching for cancer patients

https://www.clintrialfinder.info
1•chncwang•57m ago•0 comments

Show HN: L88 – A Local RAG System on 8GB VRAM (Need Architecture Feedback)

https://github.com/Hundred-Trillion/L88-Full
1•adithyadrdo•1h ago•0 comments

Simulating the hardest Physics Problems in Python [video]

https://www.youtube.com/watch?v=M_OOwhA2fY8
1•chii•1h ago•0 comments

Show HN: We scanned 500 ClawHub skills for security risks – 10% were dangerous

1•yusufjacobs•1h ago•0 comments