‼️Do not npm install or deploy anything right now
Supply chain attack on axios 1.14.1 - even if you don’t use axios it may be a nested dep.
Pin versions or wait until this is resolved
@npmjs@GHSecurityLab there is an active supply chain attack on axios@1.14.1 which pulls in a malicious package published today - plain-crypto-js@4.2.1 - someone took over a maintainer account for Axios
Hey @kentcdodds you have been talking about context bloat and context engineering in the MCP/agent space. i wrote a deep dive on why AI agents actually fail (benchmarks, $47k runaway loops, error compounding) and why context engineering not bigger models is the fix.
i think the missing layer is structured memory that decides what the model sees at each step, not dumping everything into the window.
Would love your take on whether i'm right about the problem and the solution:
dev.to/fnlog0/your-new-colle…
Today we're launching local scheduled tasks in Claude Code desktop.
Create a schedule for tasks that you want to run regularly. They'll run as long as your computer is awake.
Introducing EVMbench—a new benchmark that measures how well AI agents can detect, exploit, and patch high-severity smart contract vulnerabilities. openai.com/index/introducing…
Introducing json-render
AI-generated UI. Deterministic output.
1. Define your component catalog
2. AI steams JSON
3. Render interactive UI
Let users prompt dashboards, widgets and apps - safely constrained to components and actions you define
Skillsync helps companies find elite (but overlooked!) engineers on GitHub based on what they have actually built.
It analyzes public GitHub contributions and turns them into structured skill profiles that recruiters & hiring managers can search.
Congrats to @narsagna and @nishantjosh on the launch!
ycombinator.com/launches/PAP…
🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
The malicious payload works by silently swapping crypto addresses on the fly to steal funds.
If you use a hardware wallet, pay attention to every transaction before signing and you're safe.
If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.
It’s still unclear whether the attacker is also stealing seeds from software wallets directly at this stage.
Excellent report here: jdstaerk.substack.com/p/we-j…
Haxo Labs is rethinking how digital infrastructure is imagined, designed, and deployed across Fintech, SaaS, AI, and Blockchain.
We build systems with clarity, not chaos.
Our goal: tech that lasts longer than the hype.
See @mitchellh's AI coding workflow in action! Tomorrow at 3pm EST, we're exploring his recent PRs and discussing where agentic engineering is headed—the wins, the gaps, and the messy middle. Live Q&A included!
Sign up or add the event directly to your calendar: zed.dev/agentic-engineering
Monad Testnet update:
Max contract size has been increased to 128 kb (from 24.5 kb, the limit on Ethereum).
There's enough to worry about already, contract size limits shouldn't be one of them!
Viem 2.23 now has support for better call simulation, including asset changes, gas used, and logs with the `simulateCalls` API!
Image 1: Usage
Image 2: Response (asset changes)
Image 3: Response (results, logs & gas used)
Powered by `eth_simulateV1` – a successor to multicall.
Considering a switch from LangChain to AISDK?
Here's why you might want to: AISDK offers a more streamlined approach to AI integration, with fewer complexities and faster deployment.
The choice depends on your project needs, but AISDK is definitely worth exploring.
This week's updates: @AppRealm
✅ Access Realm Search from anywhere
✅ Updated 'Add to Realm' UIs
✅ Bug fixes and optimisation's
Stay tuned for the release at the end of this week!