frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Blueprint of a North Korean Attack on Open-Source

https://casco.com/blog/the-blueprint-of-a-north-korean-attack-on-open-source
12•brene•1h ago

Comments

brene•1h ago
Author here. We were analyzing a compromised contributor account targeting better-auth when we noticed something interesting about the attack vector. Most coverage of supply chain attacks focuses on the "what happened" but I wanted to document the "how it actually works" with the deobfuscated code.

Wwo things stood out: 1. hiding the payload in next.config.mjs is clever because GitHub's UI truncates long lines so the malicious string is literally invisible when scrolling through the file. second, storing the c2 payload on binance smart chain means theres no server to take down. The axios attack was mitigated by removing the GitHub-hosted payload. This one can't be.

2. found 30+ repos with the same signature string. Pretty sure there's way more we didn't catch with basic string matching.

happy to answer questions about the deobfuscation process or the c2 protocol analysis.

iannacl•1h ago
The blockchain angle to circumvent takedowns of the payload hosting here is really interesting.
rafaveira3•1h ago
break one maintainer, own the ecosystem. btw, beautiful graphs

Show HN: Turn your GitHub activity into a weekly dev blog on GitHub Pages

https://github.com/deariary/github-weekly-reporter
1•unhappychoice•15s ago•0 comments

I Built Multi-Agent Collaboration Before Agent Teams Existed

https://www.purecontext.dev/blog/multi-agent-collaboration-before-agent-teams
1•jeffreese•31s ago•0 comments

Durable Researcher

https://github.com/steel-experiments/durable-researcher
1•nkko•51s ago•0 comments

ICE arrested more than 800 people after tips from US airport security agency

https://www.reuters.com/world/ice-arrested-more-than-800-people-after-tips-us-airport-security-ag...
1•gostsamo•2m ago•0 comments

Gitmore – AI summaries of your GitHub/GitLab activity (no more manual reports)

https://gitmore.io
1•SiwarGrami•3m ago•0 comments

Anthropic Set to Preview Powerful 'Mythos' Model to Ward Off AI Cyberthreats

https://www.wsj.com/tech/ai/anthropic-set-to-preview-powerful-mythos-model-to-ward-off-ai-cyberth...
1•bengebre•4m ago•0 comments

gitsugi; Mend the gaps in your GitHub contribution graph with gold

https://github.com/johnrbell/gitsugi
1•jfigure•5m ago•0 comments

"Inference Noise", AI slop's older brother

https://uxcontent.com/inference-noise-ai-vs-human-writing/
2•haubey•11m ago•0 comments

System Card: Claude Mythos Preview [pdf]

https://www-cdn.anthropic.com/53566bf5440a10affd749724787c8913a2ae0841.pdf
23•be7a•11m ago•4 comments

Show HN: I turned the Pong Wars simulation into a multiplayer game

https://github.com/mayerwin/pong-wars-reloaded
2•mayerwin•12m ago•0 comments

CIA used "long-range quantum magnetometry" called "Ghost Murmur" in Iran

https://nypost.com/2026/04/07/us-news/ghost-murmur-a-never-used-secret-tool-deployed-to-find-lost...
5•bhouston•12m ago•3 comments

First criticality for Indian fast breeder reactor

https://www.world-nuclear-news.org/articles/first-criticality-for-indian-fast-breeder-reactor
1•philipkglass•13m ago•0 comments

One async Rust codebase for STM32, Linux and the browser

https://aimdb.dev/blog/building-aimdb-one-async-api
2•sounds-like-lx•13m ago•0 comments

Meet The Hero: Jane Elliott

https://www.lowellmilkencenter.org/programs/projects/view/brown-eyes-blue-eyes/hero
2•thunderbong•15m ago•0 comments

Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure

https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
6•jaredwiener•15m ago•0 comments

A C++ library that reduces tail latency in RAM

https://twitter.com/lauriewired/status/2041567004814098542
2•mvdwoord•17m ago•0 comments

Assessing Claude Mythos Preview's cybersecurity capabilities

https://red.anthropic.com/2026/mythos-preview/
8•sweis•18m ago•0 comments

Is there any 'media' similar to HN? like the minimalist format

2•elmlabs•19m ago•0 comments

Alize – A daily newsletter that watches YouTube for you

https://alize.me
3•yasintoy•20m ago•0 comments

Project Glasswing: Securing critical software for the AI era

https://www.anthropic.com/glasswing
61•Ryan5453•20m ago•11 comments

Self-Promotion on HN

3•denotes•21m ago•0 comments

Facevitals – Lightweight rPPG vital signs monitoring (No GPU required)

https://github.com/Ninjexxx/facevitals
2•artzeraw•22m ago•0 comments

Reshape, not replace: What AI is changing about our work today

https://www.mjeggleton.com/blog/the-work-to-do-the-work
2•michaelje•22m ago•0 comments

War Is the Best VC Pitch Nobody Wants to Give

https://rawtext.io/signal/war-is-the-best-venture-capital-pitch/
3•just_a_watcher•25m ago•2 comments

AI replacing radiologists: Docs slam Nvidia, Anthropic CEOs for false info

https://timesofindia.indiatimes.com/technology/tech-news/as-ceo-of-americas-largest-public-hospit...
3•rustoo•25m ago•0 comments

Donald Trump is threatening the extinction of an 'entire civilization' tonight

https://isdonaldtrumpalive.com/donald-trump-is-alive-and-threatening-the-extinction-of-an-entire-...
4•only_in_america•25m ago•1 comments

Ask HN: What are you working on? (April 2026) (Non AI)

2•cousin_it•28m ago•9 comments

Show HN: PromptJuggler – A dev env and runner for prompts, workflows, agents

https://promptjuggler.com
2•TamasSzigeti•28m ago•0 comments

AI-powered roasts (and Solutions) for your product

https://roastcraft.app/en
2•techguydiy•29m ago•0 comments

I made Claude Code run on my Apple Watch

https://twitter.com/whosmatu/status/2041341039466971508
2•immatheus•30m ago•0 comments