Weekly news around the world of ecommerce, retail & technology. Host of the V Spot - home to the eCommerce Nearly News. substack.com/@vinnyobrien

Joined March 2019
20 Photos and videos
TheVSpotNews retweeted
Very excited about this
Vercel is partnering with and integrating Shopify. Starting with @v0, you can now prompt a Next.js Shopify store in seconds. The old tradeoff was “easy monolith” or “costly headless”. No more. Easy @nextjs Shopify storefronts with no scale or sophistication ceiling.
36
34
822
135,372
Re-introducing friction. A component link to the success of automation, agentism and the increasing adoption of new but the same ol' shopping methods - lnkd.in/eZ333sGM
1
6
TheVSpotNews retweeted
A family from Shannon Vale, captures a close encounter with a basking shark while kayaking. The video, shared with the Southern Star, shows the shark's dorsal fin breaking the surface of the water as it swims near the kayak. The underwater footage provides a glimpse of the shark's massive body and gills as it filter-feeds on plankton.
1
13
78
13,031
TheVSpotNews retweeted
Adidas lanzó un corto de 5 minutos protagonizado por Timothée Chalamet donde recluta a Bellingham, Yamal y Trinity Rodman para vencer a un equipo de fútbol callejero y efectivamente es cine. Messi, Zidane, Beckham, Del Piero, Bad Bunny… denle el Oscar.

72
1,152
7,913
575,575
TheVSpotNews retweeted
10/10
Ben Sasse comes out in favor of sex and babies. Both are great. Highly recommend.
67
173
3,831
200,191
TheVSpotNews retweeted
This. Is. A. Masterpiece. Of. Socio-Economic Analysis.
The enshittification of Ireland and the hollowing out of our institutions is the single largest threat to Irish civil society and prosperity. In this damning piece, I'm going into more detail about the graph I posted yesterday: why it's happening in Ireland, why the way we're thinking about the protests is entirely wrong, and what this means for our collective governance. Link to the article is below!
22
60
319
24,125
TheVSpotNews retweeted
New version of Universal Commerce Protocol (UCP 2026-04-08) just got finalized. Carts (!), Catalog discovery features, Order status,, Signals support, ... Big step step function upgrade for agentic commerce. ucp.dev/2026-04-08/specifica… Coming soon to every Shopify storefront.
21
33
417
37,052
Moda
Not saying Canva should be worried. But this is the first thing I've seen in a while that made me think someone's finally coming for them.
1
1
22
TheVSpotNews retweeted
Mar 24
🚨 Andrej Karpathy just explained the scariest thing happening in software right now.. someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.. SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything.. and here's the part that should terrify every developer alive.. the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks.. one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen.. Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned.. vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
279
2,208
13,811
3,174,981
TheVSpotNews retweeted
A new virus has arrived which targets the system that powers Apple devices. Here’s what you need to know 👇 Victims of the malware should consult a competent cyber security professional and report the crime to their local Garda Station. #KeepingPeopleSafe
24
96
280
111,996
TheVSpotNews retweeted
Two minutes on Donald Trump's mixed messages on the war with Iran. Produced by Katerina Karelli. The BBC News live page on the war is here: bbc.co.uk/news/live/ce84073m…
83
726
1,960
325,501