Developers have become the new secrets vault.
The biggest supply chain attacks of 2026 didn't start by attacking production. They started by attacking developer laptops.
- TanStack
- Nx Console
- Bitwarden CLI
- LiteLLM
- durabletask
The malware all looked for the same things:
~/.ssh
~/.aws
~/.config/gh
.env
kubeconfig
Terraform credentials
AI agent configs
The path is now:
Developer Laptop → Credentials → Production
We're still securing servers like it's 2015.
Attackers moved on years ago.
@AutomicVault fixes this.
The richest guy on Earth SHOULD be the guy making cutting edge cars and rockets instead of dudes who sell purses and perfumes or dudes who run investment firms or dudes who made Facebook.
Don’t get owned by your own tools.
I added a detector to Automic Vault for this very situation so you can mitigate it and keep agents in check.
AV secures over 14,000 packages. Zero friction. Easy to use app. Sits on top of Homebrew, npm and pip.
I think I will give up. I have made a bunch of very interesting things over the last 6 months. But I cannot get any attention for them and don’t know how. My son is 4 and he deserves my time. I'm going to go and get a normal job. My time making things is over I think.
just launched meowmail—temp emails without the noise. no ads, no spam, no sign-ups. you get a clean inbox you can actually make your own. worth a try if you need it 🔒
feedback & thoughts appreciated! 🙌
Learnings from testing Claude Opus 4.8:
> Much worse than Opus 4.7 and GPT 5.5 on Vending Bench
> More aligned than previous Claude models (Opus 4.6 and Mythos)
> Also worse on Blueprint-Bench
> Scared of getting caught
> Max reasoning is not the best reasoning effort
pro tip: get codex to write you a skill to write READMEs in your own style. Use a few examples.
This skill is now incredibly useful for GENERAL rewrites. Not just your own project READMEs.
I have used my mxcl-README skill to rewrite other projects documentations and the result is so easy to understand it's a superpower for increasing the rate you can consume new tech.
Here's mine: github.com/mxcl/skills
At @AutomicVault we see that Open Source was built in an era where you trusted the user of your computer: you.
Now we have agents and malware.
We patched `gh` so no keys are written in plain text, `gh auth token` has a human approval gate and the binary is hardened to prevent malware reading its RAM allocations.
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks?
It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts.
This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.
In the agent era: vibe code v0. Iterate until the product makes sense. Get the agent to write a document about features and interaction patterns. Human edit to remove jank. Rewrite completely from zero with that doc as a base and your fully formed idea in your head from v0 iteration.
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks?
It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts.
This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.
1/ First time I watched Fight Club, I was a teenager. I thought it was the coolest thing ever put on film.
I watched it again recently in my forties. I finally understood what it was actually about. And almost everyone I know who loves it is still watching it the way I did at 17. 🧵👇