Show HN: GitHits Public Beta 0.9
GitHits launched its public beta 0.9, a CLI and local MCP server that gives coding agents access to open-source code behind project dependencies. The tool indexes open-source code and documentation, a…
GitHits launched its public beta 0.9, a CLI and local MCP server that gives coding agents access to open-source code behind project dependencies. The tool indexes open-source code and documentation, a…
A developer released Pi, a coding agent that runs entirely on a local machine without API keys or cloud dependencies. Pi works with a local llama.cpp server hosting Google Gemma 4 models, enabling off…
A developer received a LinkedIn message from a recruiter at a crypto startup asking to review a GitHub repository before a technical interview. The repository contained a backdoor in npm's prepare scr…
A developer released cPanel MCP, a tool enabling AI agents to administer cPanel servers via WHM and UAPI, on npmjs.com. The tool dynamically probes server versions to avoid documentation drift and has…
A high school student in Italy built TITAN (Token Intelligence Through Agent Narrowing), a zero-dependency CLI framework that compresses AI coding agent token consumption by 70% to 85% without degradi…
A security researcher received a LinkedIn message from a recruiter at a crypto startup asking them to review a GitHub repo. The repo contained a backdoor that would execute arbitrary code when depende…
A developer analyzed Google Search Console data for their indie tool Mimi Seed and found that optimizing for generative engine optimization (GEO) is effectively just traditional SEO. The real issue wa…
WastedCode released TrueCast, a CLI and plugin system that installs portable expert personas—such as product manager, architect, and security reviewer—into Claude Code sessions. The tool provides vers…
Researchers presented a method for cross-language detection of malicious packages in npm and PyPI ecosystems at a 2023 conference. The approach aims to identify security threats across JavaScript and …
A developer explains why AI agents often ignore explicit rules, using a React Native project example where a rule against using 'pnpm add' for native packages was broken, causing a build failure. The …
Around 1,500 packages in the Arch User Repository (AUR) were compromised with rootkit-like malware. The attacker exploited a policy that allows takeover of orphaned packages after a two-week waiting p…
Omegacode, an agent-agnostic workflow runner, launches as an open-source tool that orchestrates multiple coding agents including Claude Code, Codex, OpenCode, and pi using a deterministic DSL. The too…
A developer built ctxstash, a zero-dependency command-line tool that packs a codebase into a single Markdown file with a token count estimate, making it easier to share code with LLMs like ChatGPT and…
Socket's Threat Research team identified 23 new malicious PyPI packages in the Mini Shai-Hulud, Miasma, and Hades supply chain attacks, expanding the campaign to 471 artifacts across npm and PyPI. The…
An AI agent scaffolded a project using an outdated 2020 version because npx resolved to an old package version without engine constraints, due to npm's version resolution prioritizing engine compatibi…
The FiatDock team migrated its entire stack—Express server, fetch client, and MCP server—from x402 v1 to protocol v2 in a single evening, eliminating all 24 transitive npm vulnerabilities in the proce…
AI agents using npx without specifying a version can inadvertently scaffold projects from outdated templates due to npm's engine compatibility resolution, which prioritizes older versions without engi…
PostHog co-founder James Hawkins warns that the fragmentation of coding interfaces—from Slack bots to AI agents and MCP servers—is expanding the attack surface on developer devices faster than securit…
In May 2026, two supply-chain attacks targeted AI coding tools including Claude Code and Cursor, with one malicious VS Code extension stealing npm, AWS, GitHub, and SSH credentials from 6,000 develope…
A new variant of the Miasma worm has been discovered exploiting npm's binding.gyp build file to execute malicious code during package installation, bypassing traditional package.json script audits. Th…