The Rapture of the Programming Languages
Generative AI coding assistants are making programming language popularity less relevant, as tools like Claude Code can work with older languages like Perl if sufficient documentation exists. The auth…
Generative AI coding assistants are making programming language popularity less relevant, as tools like Claude Code can work with older languages like Perl if sufficient documentation exists. The auth…
A developer created a Toy Story-themed analogy for the open-source ecosystem, personifying tools like Python's cpython and Facebook's React as characters. The story explores conflicts between legacy a…
A new analysis warns that CLI token compression tools like RTK, despite promising up to 90% cost savings, introduce dangerous silent failures by stripping critical terminal output, leading to agent ha…
The npm account 'ai' publishes seven packages that collectively receive 964 million weekly downloads, yet none have npm provenance attestations. This single-publisher, no-provenance pattern mirrors re…
A new open-source CLI tool, mcp-customs, scans MCP servers for security risks before installation, running fully offline with no telemetry. It checks for issues like shell injection, path traversal, a…
A developer built NPM Safety Guard, a free IDE extension that scans package.json and lockfiles for malicious npm packages across 22 detection layers. The tool catches typosquats, AI-hallucinated packa…
Microsoft's VS Code 1.123, released June 3, introduces a two-hour delay before newly published extension versions auto-update, aiming to mitigate supply chain attacks by providing a window to catch ma…
Attackers are increasingly targeting developer endpoints to steal credentials, as demonstrated by supply chain attacks like Megalodon, TrapDoor, and Miasma. GitGuardian's new Developer Endpoint Protec…
A developer built a Docker MCP server with 50 tools after finding 11 existing packages fragmented across different licenses and feature sets. The server, which has achieved over 3,042 weekly downloads…
In June 2026, attackers hijacked the npm contributor account 'ehindero' to mass-publish malicious versions of 144 packages under the @mastra namespace, in what security researchers from JFrog, SafeDep…
An attacker hijacked a dormant contributor account and published malicious versions of 144 packages under the @mastra npm scope between 01:15 and 02:36 UTC, targeting the TypeScript AI agent framework…
On June 17, 2026, an attacker compromised the @mastra npm organization and added the typosquat package easy-day-js as a dependency across 140+ Mastra AI framework packages, exposing over 1.1 million w…
A supply chain attack compromised over 140 npm packages in the @mastra scope, including @mastra/core with 918K weekly downloads, by injecting a malicious dependency that executes a postinstall script …
The StepSecurity Threat Intelligence Team has identified that multiple @mastra npm packages have been compromised. The security breach was disclosed in a GitHub issue on the mastra-ai/mastra repositor…
Socket Threat Research identified shai_hulululud@1.0.48596, an npm package designed to probe AI-based malware scanners using prompt injection, token flooding, and obfuscated JavaScript. The package co…
Developer released Pacwich, a lightweight monorepo tool that works with Bun, npm, or pnpm, replacing the earlier bun-workspaces package. The tool requires zero configuration and uses plain package.jso…
Muster 1.0.0, a new CLI tool from developer Garrison, tests AI agent stacks across seven layers including persona, skills, SOP, tools, memory, heartbeat, and A2A. It performs both static validation an…
JerrySniffs launched an MCP server and API suite for web and social media search, offering credit-based access to Google, Twitter/X, Reddit, and page-to-markdown endpoints with no recurring subscripti…
Microsoft's platform teams discovered that AI coding agents ignore new CLI tools and default to older, more documented predecessors due to training data gravity, even when explicitly instructed otherw…
A developer built RagScope, an open-source tool that audits RAG pipelines to reveal wasted retrieval latency from chunks fetched but never used in the final prompt. The tool uses OpenTelemetry traces …