seth

@seth.computer

Trying to make computers do more good for humans. Engineering @ Zapier. Community @ devICT. https://seth.computer

🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Our campaign page includes all affected packages/versions.

Socket@socket.dev · yesterday

🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads. The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.

“The creators have unleashed another weapon on the maintainers: turning loose legions of people to build new buildings and bridges without any thought to architecture or city planning.” Great read. Especially appreciate this call out to the importance of maintening our critical OSS infrastructure.

Sam Learner@samlearner.bsky.social · 4w ago

wrote for the magazine about the open source software that underpins our digital lives, how it is being upended by AI code tools, and about maintainers as.ft.com/r/b7f62212-9...