frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

'No Way to Prevent This,' Says Only Package Manager Where This Regularly Happens

https://kevinpatel.xyz/posts/no-way-to-prevent-this/
46•alligatorplum•1h ago

Comments

btown•18m ago
For those unfamiliar with the context: https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_...
Modified3019•14m ago
Same vibe: https://www.youtube.com/watch?v=lOTyUfOHgas
p-e-w•12m ago
With the recent high-profile attacks on PyPI packages, it’s no longer true that npm is the “only package manager where this regularly happens”.

In fact, pip is much more dangerous than npm because it lacks a lockfile. uv fixes that, but adoption is proceeding at a snail’s pace.

aselimov3•10m ago
What are the actual guarantees that go/Rust make that Python/npm don’t? It seems like it might just be that Python/npm are juicier targets? I’m starting to try and avoid all third party packages
cookiengineer•2m ago
I suppose that go's go:generate workflow can also be abused to land a worm like the ones spreading via npm, as you can build programs that just scrape the whole hard drive for git projects and patch the go.mod dependencies there, and you could also just write this in go as a toolchain script, for example.

NPM's achilles is the postinstall step which can run arbitrary commands and shell scripts without the user having any way to intervene.

Dependencies must be run in isolated chroot sandboxes or better, inside containers. That would be the only way to mitigate this problem, as the filesystem of the operating system must be separated from the filesystem of the development workflow.

On top of that most host based firewalls are per-binary instead of per-cmdline. That leads to the warnings and rules relying on that e.g. "python" or "nodejs" getting network access allowlisted, instead of say "nodejs myworm.js".

exabrial•8m ago
I really don't understand why the npm project cannot embrace PGP as an ambulatory 'good enough' solution.
loloquwowndueo•6m ago
The NIH mentality in the ecosystem would result in a JavaScript pgp library which itself would be an npm package and subject to supply chain attacks. lol.

Fix pathological performance in trait solver

https://github.com/rust-lang/rust/pull/155355
1•Jyaif•2m ago•0 comments

Pinote – A lightweight floating Markdown scratchpad app

https://github.com/ImFeH2/pinote
1•indigodaddy•3m ago•0 comments

I built a machine that can make you rich with math [video]

https://www.youtube.com/watch?v=2UM4j1_xEs0
1•tzvc•4m ago•0 comments

Senior NIAID Official Indicted for Concealing Records During Covid Pandemic

https://www.justice.gov/opa/pr/former-senior-niaid-official-indicted-concealing-federal-records-d...
2•Jimmc414•5m ago•1 comments

YC startup Luel appears to have copied Kled

https://twitter.com/avipat_/status/2055384102409253056
2•tjek•9m ago•1 comments

Show HN: Nexa-Gauge – LLM eval framework, now with self-hosted model support

https://github.com/harnexa/nexa-gauge
1•Sardhendu•10m ago•0 comments

Ask HN: What Happened to ssh-audit.com?

1•Bender•11m ago•0 comments

Show HN: Plan-Graph based code generation with LLMs

https://github.com/agrin96/VibegraphGenerator
1•ag_rin•15m ago•0 comments

Kinetic typography: the what, why, and how

https://www.linearity.io/blog/kinetic-typography/
1•argee•22m ago•0 comments

Symposia AI

https://www.trysymposiaai.com/landing
1•CarlosEdu•23m ago•1 comments

Solving CartPole in 8 Weights

https://cartpole.neocities.org/
3•georgehotz•24m ago•0 comments

Magical Realism: "Northern Exposure" 25 Years Later (2015)

https://www.rogerebert.com/streaming/magical-realism-nothern-exposure-25-years-later
1•walterbell•24m ago•0 comments

Show HN: Wyndup – share a live countdown with your podcast guest

https://wyndup.net
1•ardwino•28m ago•0 comments

Elastic Cloud on Kubernetes, simplified: zone awareness, restarts, and mTLS

https://www.elastic.co/search-labs/blog/elasticsearch-kubernetes-zone-awareness-restarts-mtls
1•eigenBasis•29m ago•0 comments

Jane Street's approach to AI adoption throughout their SDLC [video]

https://www.youtube.com/watch?v=rUYP4C29yCw
2•devdoshi•31m ago•1 comments

Brovan: Binary user-mode emulator for x86_64

https://github.com/AdvDebug/Brovan
1•AdvDebugy•32m ago•0 comments

WikiProject Editor Retention

https://en.wikipedia.org/wiki/Wikipedia:WikiProject_Editor_Retention
1•sshh12•33m ago•1 comments

A Compression Tool for LLM Reads. Est. 60-95% Fewer Tokens

https://github.com/chopratejas/headroom
1•botacode•33m ago•0 comments

North America's largest commuter rail system faces a potential shutdown

https://apnews.com/article/lirr-new-york-commuter-rail-strike-union-eefab0d1f91470934fb89bd1809d0a94
3•petethomas•36m ago•3 comments

Random.website

https://random.website
2•npilk•36m ago•0 comments

Humanoid robots won't surprise us when they arrive

https://philipotoole.com/humanoid-robots-wont-surprise-us-when-they-appear/
2•otoolep•40m ago•0 comments

Thorchain halts trading after $10M cross-chain exploitRUNE token drops 12%

https://www.coindesk.com/tech/2026/05/15/thorchain-halts-trading-after-usd10-million-cross-chain-...
1•LUZUVYY•45m ago•0 comments

Engineer creates starwars inspired air bike

https://volonaut.com
1•nirkalimi•46m ago•0 comments

How to bypass Anti-Bots in 2026

https://roundproxies.com/blog/how-to-bypass-anti-bots/
2•majorchord•47m ago•0 comments

Python by Example Using Cloudflare Dynamic Workers

https://www.pythonbyexample.dev/
2•adewale•47m ago•1 comments

Lost in Translation: Text Message Spoofing via Email [pdf]

https://sumanthvrao.github.io/papers/rao-oakland-2026.pdf
3•yechs•48m ago•1 comments

New quantum algorithm solves "impossible" materials problem in seconds

https://www.sciencedaily.com/releases/2026/05/260512202355.htm
3•maxloh•48m ago•1 comments

What Is Rails-Way?

https://paweldabrowski.com/farewell-to-rails-way/what-is-rails-way
3•thunderbong•51m ago•0 comments

SpaceX targets June 11 IPO pricing, picks Nasdaq for historic market debut

https://www.coindesk.com/markets/2026/05/15/spacex-targets-june-11-ipo-pricing-picks-nasdaq-for-h...
2•LUZUVYY•51m ago•0 comments

Auto Rebaser v2 – browser-side GitHub PR housekeeping, now multi-account

https://github.com/bradygrapentine/auto-rebaser
2•bgrapentine•55m ago•0 comments