frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

DoNotNotify is now Open Source

https://donotnotify.com/opensource.html
219•awaaz•5h ago•38 comments

Why E cores make Apple Silicon fast

https://eclecticlight.co/2026/02/08/last-week-on-my-mac-why-e-cores-make-apple-silicon-fast/
24•ingve•1h ago•2 comments

Dave Farber has passed away

https://lists.nanog.org/archives/list/nanog@lists.nanog.org/thread/TSNPJVFH4DKLINIKSMRIIVNHDG5XKJCM/
27•vitplister•1h ago•6 comments

Matchlock: Linux-based sandboxing for AI agents

https://github.com/jingkaihe/matchlock
47•jingkai_he•4h ago•10 comments

Reverse Engineering Raiders of the Lost Ark for the Atari 2600

https://github.com/joshuanwalker/Raiders2600
17•pacod•3h ago•1 comments

Show HN: LocalGPT – A local-first AI assistant in Rust with persistent memory

https://github.com/localgpt-app/localgpt
249•yi_wang•11h ago•125 comments

Haskell for all: Beyond agentic coding

https://haskellforall.com/2026/02/beyond-agentic-coding
154•RebelPotato•10h ago•45 comments

Curating a Show on My Ineffable Mother, Ursula K. Le Guin

https://hyperallergic.com/curating-a-show-on-my-ineffable-mother-ursula-k-le-guin/
6•bryanrasmussen•2h ago•0 comments

SectorC: A C Compiler in 512 bytes (2023)

https://xorvoid.com/sectorc.html
326•valyala•19h ago•66 comments

(AI) Slop Terrifies Me

https://ezhik.jp/ai-slop-terrifies-me/
51•Ezhik•2h ago•29 comments

Rabbit Ear "Origami": programmable origami in the browser (JS)

https://rabbitear.org/book/origami.html
17•molszanski•3d ago•3 comments

LLMs as the new high level language

https://federicopereiro.com/llm-high/
141•swah•5d ago•264 comments

The Legacy of Daniel Kahneman: A Personal View (2025)

https://ejpe.org/journal/article/view/1075/753
11•cainxinth•3d ago•0 comments

The Architecture of Open Source Applications (Volume 1) Berkeley DB

https://aosabook.org/en/v1/bdb.html
48•grep_it•5d ago•8 comments

Software factories and the agentic moment

https://factory.strongdm.ai/
245•mellosouls•21h ago•407 comments

Modern and Antique Technologies Reveal a Dynamic Cosmos

https://www.quantamagazine.org/how-modern-and-antique-technologies-reveal-a-dynamic-cosmos-20260202/
11•sohkamyung•5d ago•0 comments

Speed up responses with fast mode

https://code.claude.com/docs/en/fast-mode
197•surprisetalk•18h ago•204 comments

A11yJSON: A standard to describe the accessibility of the physical world

https://sozialhelden.github.io/a11yjson/
7•robin_reala•5d ago•0 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
200•AlexeyBrin•1d ago•40 comments

uLauncher

https://github.com/jrpie/launcher
42•dtj1123•5d ago•11 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
217•vinhnx•22h ago•26 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
379•jesperordrup•1d ago•121 comments

Brookhaven Lab's RHIC concludes 25-year run with final collisions

https://www.hpcwire.com/off-the-wire/brookhaven-labs-rhic-concludes-25-year-run-with-final-collis...
86•gnufx•17h ago•66 comments

Wood Gas Vehicles: Firewood in the Fuel Tank (2010)

https://solar.lowtechmagazine.com/2010/01/wood-gas-vehicles-firewood-in-the-fuel-tank/
60•Rygian•3d ago•29 comments

LineageOS 23.2

https://lineageos.org/Changelog-31/
93•pentagrama•7h ago•26 comments

First Proof

https://arxiv.org/abs/2602.05192
159•samasblack•21h ago•97 comments

Show HN: I saw this cool navigation reveal, so I made a simple HTML+CSS version

https://github.com/Momciloo/fun-with-clip-path
120•momciloo•19h ago•29 comments

In the Australian outback, we're listening for nuclear tests

https://www.abc.net.au/news/2026-02-08/australian-outback-nuclear-tests-listening-warramunga-faci...
22•defrost•3h ago•4 comments

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
624•theblazehen•3d ago•226 comments

Arcan Explained – A browser for different webs

https://arcan-fe.com/2026/01/26/arcan-explained-a-browser-for-different-webs/
3•walterbell•4h ago•0 comments
Open in hackernews

Shai Hulud launches second supply-chain attack

https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
352•birdculture•2mo ago

Comments

benzible•2mo ago
Dup https://news.ycombinator.com/item?id=46032539 [edit: not a dup!]
swsieber•2mo ago
This article has quite a bit more information though.
dang•2mo ago
Thanks—I've added this link to the toptext at https://news.ycombinator.com/item?id=46032539.
thih9•2mo ago
Not a dup, this is a different article about the same event, with different information too.
a4isms•2mo ago
Please use the word "Dup" for a resubmission of the same link and "See also" for a different submission.
neogodless•2mo ago
See also: https://news.ycombinator.com/item?id=46032539 Shai-Hulud Returns: Over 300 NPM Packages Infected (helixguard.ai)

~6 hours ago | 430 comments

dang•2mo ago
Ok, we've merged the (relevant) comments thither. Thanks!

Edit: Here's a bit of explanation for those curious. Even though the links are different, the test we use for whether to merge threads is whether they are substantially the same story vs. whether the two links will lead to substantially different discussion. In this case it's clear that it's the same discussion, so I merged them.

Since the second link has additional information, I've added it to the toptext of the original post. That way people can look at both.

QuantumNomad_•2mo ago
Typo in title. Current title of HN post says:

> SHA1-Hulud the Second Comming – Postman, Zapier, PostHog All Compromised via NPM

Should be Shai-Hulud, not SHA1-Hulud.

adzm•2mo ago
That said, the secrets are uploaded to a repo named `Sha1-Hulud: The Second Coming`
zahlman•2mo ago
Ah, I missed that detail.
zahlman•2mo ago
I don't know why you were downvoted. The actual page does not say SHA1, the attack as far as I know is not related to the SHA1 algorithm, and the name of the worm isn't intended as that sort of pun.
pezezin•2mo ago
The worm itself is posting the secrets in Github with the name Sha1-hulud: https://github.com/search?q=sha1-hulud&type=repositories
cyberpunk•2mo ago
Yikes. AWS secrets galore in the couple I decoded (double base64)...

I'm surprised github is leaving these up.

galangalalgol•2mo ago
At this point it likely helps the defenders more than those that would use them doesn't it?
meowface•2mo ago
I am guessing they don't intend to and will be removing them with urgency.
AlexandrB•2mo ago
Also "coming" only has one "m". Or is this some kind of pun?
ChrisArchitect•2mo ago
[dupe] Discussion: https://news.ycombinator.com/item?id=46032539
welder•2mo ago
Python script to check if any of your repos have the listed compromised packages in pnpm or npm lock files:

https://chatgpt.com/s/t_6924b232a8f88191a146a510c6631143

artisin•2mo ago
Worth mentioning that Bubblewrap[1] (bwrap) can remove most npm/node attack vectors or, at the very least, limit the damage from running arbitrary code during install/execution. Far from a silver bullet, and you'll want to combine it with a simple wrapper script to avoid dinking around with all its arguments, but it beats dealing with rootless Podman containers.

[1] https://github.com/containers/bubblewrap

port11•2mo ago
This looks really interesting, but it sounds like it's as complicated to setup as rootless Podman — which is to say not _that_ complicated. Anyone using this with Node or Deno successfully?
bunnybender•2mo ago
From my bookmarks (2023): https://news.ycombinator.com/item?id=36686461
port11•2mo ago
Lovely. Thank you very much!
splix•2mo ago
We made a script to avoid such situations. It checks the dependencies, just by parsing the package.json (or the lock file), checking the relevant time on npm registry, and returns error if it finds a too fresh package added.

We run it on CI for each commit/PR, and if a developer tries to commit a change that updates a JS dependency to a too recent it prevents the build from running, and so on. Basically we expect that a Supply Chain attacks on NPM would be noticed in a couple of week, and we enforce this time window to our code.

See https://github.com/emeraldpay/paranoid.js