Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • My strategy of not using dependencies at all seems to be getting stronger everyday.

    Also no LLM generated skipping this hypetrain completely. Just hand written code I can personally vouch for. Code in exchange for cash, this is professional business, Boss.

    Btw, I'm available for hire, preferably by Pre Market Fit or pre-MVP startups, email in profile.

  • Does the FBI or any other law-enforcement office follow up on these backdoors? Is this considered a crime, or even conspiracy to commit a crime, or is it only the act of using the backdoor that's a crime?

    I can also see that it's still up in NPM without any warning of any kind: - https://www.npmjs.com/package/mathmain

    But the Github repo for the package and the author are down: - https://github.com/allendev12 - https://github.com/allendev12/mathmain

  • Fascinating how intricate the target selection is on this
  • A lot of this seems to be a reminder that the CommonJS module format should just be left to die already. Not that you can't pull similar tricks with `await import()` in ESM, but you can't easily grep an entire dependency for dynamic `require()` half as easily as you can can `grep import\s*\(` for dynamic import and analysis tools for static `import` keyword are easy to use/build rather than no such thing for CommonJS.

    Someone thought I was joking when I said I always check JSR before NPM now, because I trust ESM so much more than CommonJS.

  • What is the fix for npm at this point? It has a lot of issues with the registry
  • I actually came across someone that cracked it (or use Claude/China to crack it)

    Turns out the second stage is completely broken, which is even more odd..

    https://research.veryserious.systems/lusolve-and-you-shall-r...

  • Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?
  • You need to read quite a ways before discovering that JFrog did the work of cracking the password, which enabled the rest of the analysis.

    https://research.jfrog.com/post/equation-of-compromise/

Explore Birbla archives