frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Package Managers need global hooks

https://captnemo.in/blog/2026/06/17/package-managers-need-hooks/
12•evakhoury•4d ago

Comments

TZubiri•51m ago
>Every package install is checked against the threat feed and it raises an exception if we find something malicious being installed.

So your solution is to reinvent signature based antiviruses, like Norton Antivirus and McAffee?

The problem with these 2000s approaches were that attackers could:

1- Fuzz their payloads so that they are never the same and they don't trigger detection.

2- Offload payload mechanisms so that your monitoring system needs to play cat and mouse. For example, what if the malicious code does wget https://IP/file, will you detect wget commands? Will you scan for whatever looks like a URL? Ok, what if they do "another_package_manager_like_flatpack malicious_package", will your scanner implement all package managers? What if they construct the url? "protocol + "://" + domain + file" surely your global hook thing will notice that is a url and how it is downloaded and inspect those contents as well?

3- The attacker can control the timing and infect every user at the same time, especially if they control the update mechanism of users whose security policy is to keep things patched. Even if the malicious update is not simultaneous, the malicious update can start distribution, and the attack only triggered months later (simultaneously) when enough users have downloaded it (beating latency policies).

The only solution is to do actual work and either write the thing you are trying to offload to the 'open source community, or to actually write it yourself. But of course more work is going to be put into the possibility of a magical easy solution, than on an deteriministic hard solution.

oefrha•36m ago
That’s just a wall of text for “malware detection is hard, write everything yourself, don’t use third party”. Thanks for the insight, I guess.
drdexebtjl•15m ago
This sounds like a prime new vector for malware, ironically.

Will It Mythos?

https://swelljoe.com/post/will-it-mythos/
35•mindingnever•50m ago•9 comments

Steam Machine launches today

https://store.steampowered.com/news/group/45479024/view/685257114654870245
1366•theschwa•11h ago•1231 comments

VibeThinker: 3B param model that beats Opus 4.5 on reasoning with novel SFT+GRPO

https://arxiv.org/abs/2606.16140
69•timhigins•3h ago•22 comments

GLM-5.2 – How to Run Locally

https://unsloth.ai/docs/models/glm-5.2
271•TechTechTech•7h ago•129 comments

In praise of memcached

https://jchri.st/blog/in-praise-of-memcached/
86•j03b•3h ago•32 comments

Polymarket has flooded social media with deceptive videos by paid creators

https://www.wsj.com/business/media/polymarket-social-media-bets-prediction-market-441cdeb5?st=HhTZY2
108•Vaslo•2d ago•109 comments

An Introduction to YOLO26

https://blog.roboflow.com/yolo26/
30•teleforce•3h ago•7 comments

Giant Banana Pulled Over: Driver Says Cops Have Stopped Him 100s of Times

https://cowboystatedaily.com/2026/06/18/giant-banana-pulled-over-in-montana-driver-says-cops-have...
27•speckx•2d ago•2 comments

Cyberdecks, going analog, and convivial technology

https://blog.hydroponictrash.solar/cyberdecks-going-analog-and-convivial-technology/
75•akkartik•3d ago•32 comments

Optocam Zero: a Pi Zero based digital camera made using off the shelf components

https://github.com/dorukkumkumoglu/optocamzero
135•iamnothere•9h ago•32 comments

My Mathematical Regression

https://blog.dahl.dev/posts/my-mathematical-regression/
244•aleda145•3d ago•88 comments

Japanese symbols that speak without words

https://arun.is/blog/japan-symbols/
138•msephton•9h ago•60 comments

Package Managers need global hooks

https://captnemo.in/blog/2026/06/17/package-managers-need-hooks/
12•evakhoury•4d ago•3 comments

Windows NT for GameCube/Wii

https://github.com/Wack0/entii-for-workcubes
38•zdw•3d ago•7 comments

Moebius: 0.2B image inpainting model with 10B-level performance

https://hustvl.github.io/Moebius/
258•DSemba•15h ago•65 comments

Canada plans 'nuclear renaissance' with up to 10 reactors built by 2040

https://www.cbc.ca/news/politics/federal-nuclear-strategy-9.7244509
389•geox•9h ago•240 comments

Show HN: Oak – Git alternative designed for agents

https://oak.space/oak/oak
167•zdgeier•13h ago•154 comments

1,700 free online courses from top universities

https://www.openculture.com/freeonlinecourses
110•momentmaker•3h ago•24 comments

Canyon HUD helmet for road riding

https://media-centre.canyon.com/en-INT/266866-new-canyon-heads-up-display-helmet-could-be-a-safet...
79•zh3•2d ago•91 comments

Is it time for a new Embedded Linux build system?

https://yoebuild.org/blog/time-for-a-new-build-system/
58•cbrake•4d ago•41 comments

Flock-Powered Police Chiefs Stalking Women Shows Why Warrants Are Needed

https://ipvm.com/reports/police-chiefs-track
443•jhonovich•9h ago•181 comments

Kyber (YC W23) Is Hiring a Head of Engineering

https://www.ycombinator.com/companies/kyber/jobs/FGmI8mx-head-of-engineering
1•asontha•8h ago

Ultralytics YOLO26: Unified Real-Time End-to-End Vision Models

https://arxiv.org/abs/2606.03748
13•teleforce•2h ago•0 comments

British Columbia, Time Zones, and Postgres

https://www.crunchydata.com/blog/british-columbia-and-time-zone-changes
126•sprawl_•9h ago•88 comments

Show HN: Pagecast – Publish Markdown/HTML Reports to Cloudflare Pages

https://github.com/Amal-David/pagecast
39•amaldavid•4d ago•9 comments

Job application asked for my SAT scores

https://mrmarket.lol/job-application-asked-for-my-sat-scores/
115•seltzerboys•8h ago•283 comments

ytr: YouTube Radio for Emacs

https://xenodium.com/ytr-youtube-radio-for-emacs
82•xenodium•7h ago•8 comments

Help I accidentally a wigglegram

https://lmao.center/blog/wiggle-accidents/
509•gregsadetsky•3d ago•120 comments

Show HN: Got sick of ads, so I made my own logic puzzle site

https://puzzlelair.com/
159•HaxleRose•16h ago•105 comments

Chevron signs 20-year power agreement with Microsoft for West Texas data center

https://www.chevron.com/newsroom/2026/q2/chevron-signs-20-year-power-agreement-with-microsoft-for...
132•cdrnsf•15h ago•120 comments