Claude Code's source code has been leaked via a map file in their NPM registry

Something went wrong, but don’t fret β€” let’s give it another shot. Some privacy related extensions may cause issues on x.com. Please disable them and try again.

Axios compromised on NPM – Malicious versions drop remote access trojan

https://cdn.prod.website-files.com/673b71f0790aabf30bd30bf8/69cb2363fdc3f8e8fa0460a5_blog-cover-image.png
StepSecurity identified malicious versions of the axios HTTP client library published to npm, [email protected] and [email protected], which inject a remote access trojan (RAT) dropper. Developers who installed these versions should rotate all secrets and credentials, check network logs, and downgrade to safe versions, and StepSecurity provides end-to-end npm supply chain security across three pillars: ...

Oracle slashes 30k jobs

Oracle laid off 20,000-30,000 employees, roughly 18% of its workforce, in a single email with no advance notice. The cuts are tied to Oracle's aggressive expansion into AI infrastructure, freeing up $8-10 billion in cash flow.

Artemis II is not safe to fly

https://idlewords.com/images/oig_heat_shield.jpg
NASA's Orion spacecraft has a defective heat shield that could kill the crew on Artemis II due to spalling, impact from heat shield fragments, and bolt erosion. Despite this, NASA is planning to fly the mission with a crew, citing a change in the re-entry trajectory and a new heat shield design for future missions.

The Claude Code Source Leak: fake tools, frustration regexes, undercover mode

Anthropic accidentally exposed Claude Code's source code and internal features, including anti-distillation mechanisms and a companion system. The leak reveals product roadmap details that competitors can now see and react to.

Ollama is now powered by MLX on Apple Silicon in preview

https://files.ollama.com/ollama_mlx.png
Ollama now runs faster on Apple silicon with MLX framework, leveraging GPU Neural Accelerators for speedup. Ollama 0.19 sees 1851 token/s prefill and 134 token/s decode with improved memory efficiency and model accuracy.

GitHub backs down, kills Copilot pull-request ads after backlash

https://regmedia.co.uk/2024/05/21/github1_shutterstock.jpg
GitHub removed Copilot's ability to insert ads into pull requests after backlash from developers. The feature was disabled after users complained of unwanted ads in their pull requests.

Microsoft: Copilot is for entertainment purposes only

https://cdn-dynmedia-1.microsoft.com/is/image/microsoftcorp/MSFT-Learn-Hero-Alt2_tbmnl_en-us?scl=1
You agree to these terms by using Copilot, which includes rules for using the service, protecting others, and respecting Microsoft's rights. By using Copilot, you grant Microsoft permission to use your content and agree to their terms, including the Microsoft Services Agreement and the Microsoft Privacy Statement.

Universal Claude.md – cut Claude output tokens

https://opengraph.githubassets.com/51e61dfbcd98b9faca0cb7e47d57dfdbf9b19326ffa23c3c1c377eea914ef093/drona23/claude-token-efficient
A CLAUDE.md file reduces Claude output verbosity by ~63% without code changes, targeting sycophancy, verbosity, and formatting noise. It's most beneficial for high-output use cases, and users can customize it to target specific failure modes and compose multiple files for different project types.

GitHub's Historic Uptime

GitHub's Historic Uptime All data sourced from the official status page.

OkCupid gave 3M dating-app photos to facial recognition firm, FTC says

https://cdn.arstechnica.net/wp-content/uploads/2026/03/okcupid-640x427.jpg
OkCupid and Match Group settled with the Trump administration over sharing 3 million user photos with a facial recognition firm without consent. They agreed to a permanent prohibition on misrepresenting data use and sharing, without paying a fine.

OpenAI closes funding round at an $852B valuation

https://image.cnbcfm.com/api/v1/image/108283004-17744599851774459982-44807450682-1080pnbcnews.jpg?v=1774459984&w=750&h=422&vtcrop=y
OpenAI closed a record-breaking funding round at $852 billion post-money valuation with $122 billion committed capital. The company raised $3 billion from individual investors and generates $2 billion in monthly revenue.

Google's 200M-parameter time-series foundation model with 16k context

https://opengraph.githubassets.com/3a715ab5ed97409698fa19e1f50846332c191dbd18b04dbc7566243837cc8897/google-research/timesfm
TimesFM is a pretrained time-series model by Google Research for forecasting. It can be installed via pip and used for point and quantile forecasting.

Open source CAD in the browser (Solvespace)

SolveSpace has a web version that runs in the browser with some speed penalty and bugs. It's experimental and can be hosted locally like static web content.

Claude Code users hitting usage limits 'way faster than expected'

https://regmedia.co.uk/2016/03/11/empty-gauge.jpg
Users of Claude Code are experiencing high token usage and early quota exhaustion due to a combination of factors including reduced quotas during peak hours, bugs, and unclear usage limits. Anthropic is actively investigating the issue and users are negotiating with providers over acceptable pricing and usage models for AI development.

Tell HN: Chrome says "suspicious download" when trying to download yt-dlp

Google's browser warns of a "Suspicious Download" for yt-dlp, a tool to download files from Google's servers. This is seen as browser monopoly abuse and misleading people, as Chrome also downloads files from various servers.

Italy blocks US use of Sicily air base for Middle East war

https://www.politico.eu/cdn-cgi/image/width=1160,height=772,quality=80,onerror=redirect,format=auto/wp-content/uploads/2026/03/31/GettyImages-1394407486-scaled.jpg
EU countries consider alternatives to Hungary if OrbΓ‘n wins, while progressive voters abandon center-left parties in Europe. Transatlantic tensions rise as the US rejects a Russian proposal, affecting Italy's leader and other European nations.

Slop is not necessarily the future

https://www.greptile.com/blog/ai-slopware-future/unnamed.png
AI models will write good code due to economic incentives, as good code is cheaper to generate and maintain. Economic forces will drive AI models to generate simpler, good code as it will be cheaper overall.

Why the US Navy won't blast the Iranians and 'open' Strait of Hormuz

https://responsiblestatecraft.org/media-library/image.jpg?id=65428245&width=1800&height=900&quality=74&coordinates=0%2C71%2C0%2C54
The US Navy's power projection is limited by shore-based anti-access and area denial systems, making it vulnerable to Iranian and Chinese missiles. This shift in naval warfare requires a reevaluation of investment in expensive instruments of national power.

Cohere Transcribe: Speech Recognition

https://cdn.sanity.io/images/rjtqmwfu/web3-prod/8054a4393c0b87afbde5d6d4de810d08d2c4db26-3140x1420.png?auto=format&fit=max&q=90&w=1570
Cohere Transcribe is an open-source automatic speech recognition model that achieves state-of-the-art accuracy with a low word error rate of 5.42%. It is available for download and can be used for real-world transcription tasks across 14 languages.

Ministack (Replacement for LocalStack)

https://ministack.org/logo.png
AWS services run on real infrastructure, including databases, containers, and caching. LocalStack offers a Pro version with real infrastructure support for AWS services.

A dot a day keeps the clutter away

https://scottlawsonbc.com/static/dot-system-01.jpg
The author created a simple inventory system using colored dot stickers to track usage of electronic components and tools in their lab. The system reveals patterns and helps the author decide what to keep and what to discard, making it easier to manage their collection.

U.S. stocks are set to deliver their worst quarter in nearly four years

Please enable JS and disable any ad blocker

Combinators

https://tinyapl.rubenverg.com/combinators/same.svg
Combinators are functions that refer to their arguments without modifying them. They are often represented by bird names in APL, such as Kestrel and Cardinal.

GitHub Monaspace Case Study

https://lettermatic.com/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fblwjvcya%2Fproduction%2F095a628b998a2e81d05e90e387b87b9ca3eeac08-1733x1229.png&w=1920&q=75
GitHub and Lettermatic collaborated to create Monaspace, a superfamily of five interchangeable typefaces for code editors. Monaspace offers high personalization and accessibility features, including Texture Healing, which improves legibility in monospace typefaces.

Nobody is coming to save your career

https://images.unsplash.com/photo-1620416265040-cc777cad1883?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxtaXJyb3J8ZW58MHx8fHwxNzc0Mzg0MzEyfDA&ixlib=rb-4.1.0&q=80&w=1080
Your manager is not responsible for your career growth, you must take ownership and initiate conversations about your goals. To start, tell your manager you want to grow and discuss what's needed for a promotion, then take action to make progress toward your goals.
https://raw.githubusercontent.com/timescale/pg_textsearch/main/images/tapir_and_friends_v1.0.0.png
pg_textsearch is a PostgreSQL extension for full-text search with BM25 ranking. It supports indexing, querying, and faceting with various language configurations and parameters.

Show HN: 1-Bit Bonsai, the First Commercially Viable 1-Bit LLMs

https://cdn.prod.website-files.com/697a3312d33c2cc715ec3899/69cae04a19115963ea13d12d_prism-og-img%20(2).png
PrismML's ultra-dense intelligence models, like 1-bit Bonsai, offer significant memory and energy savings. They achieve high performance and accuracy while requiring much less memory and energy than full-precision models.

RubyGems Fracture Incident Report

https://rubycentral.org/assets/images/gem-logo--badge.svg?v=f673e7d640
Ruby Central's Open Source Committee faced a crisis in September 2025 known as the "RubyGems Fracture" due to a poorly communicated process to offboard two engineers, AndrΓ© Arko and Samuel Giddens, from the RubyGems.org service. The incident led to the removal of paid contributors and highlighted the need for better policies, procedures, and communication in managing access and offboarding in ...

Mr. Chatterbox is a Victorian-era ethically trained model

https://static.simonwillison.net/static/2026/chatterbox.jpg
Trip Venturella released Mr Chatterbox, a language model trained on 28,000 Victorian-era British texts. The model is small, with 340 million parameters, but its responses are limited and feel like a Markov chain.

Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

https://storage.googleapis.com/gweb-research2023-media/original_images/Quantization-hero.gif
Google researchers warn that future quantum computers may break elliptic curve cryptography used in cryptocurrency and other systems with fewer qubits and gates than previously thought. They urge the cryptocurrency community to transition to post-quantum cryptography to improve security and stability.

Sony halts memory card shipments due to NAND shortage

https://www.techzine.eu/wp-content/uploads/2026/03/shutterstock_2573233579-768x512.jpg
Sony is temporarily halting orders for CFexpress and SD memory cards due to a NAND flash shortage driven by AI data center demand. Resumption is expected in late 2027 or 2028 when NAND production increases.

I Traced My Traffic Through a Home Tailscale Exit Node

https://tech.stonecharioteer.com/images/posts/tailscale/mesh-connection.png
You set up a Tailscale exit node on your Proxmox box to route internet traffic through your home network, achieving full-tunnel VPN-like behavior. This setup shifts trust from your current network to your controlled exit node machine.

Incident March 30th, 2026 – Accidental CDN Caching

https://s3-us-west-2.amazonaws.com/public.notion-static.com/535761c1-ecdb-4bed-b7c5-91f7eeb44bd4/Screen_Shot_2021-06-08_at_11.08.11_AM.png
Railway experienced a 52-minute incident where CDN caching was accidentally enabled for some domains, potentially serving unauthenticated data to authenticated users. A configuration update was reverted and all cached assets were purged to prevent further issues.

Accidentally created my first fork bomb with Claude Code

The user created a hook that caused a fork bomb, bricking their computer due to excessive memory usage, but luckily the computer's caching saved it from further damage. The user had been experimenting with Claude, a large language model, and built various tools to help with their work, but the experience was imperfect and costly, resulting in a $3800 API bill.

7,655 Ransomware Claims in One Year: Group, Sector, and Country Breakdown

https://ciphercue.com/img/og-card.png
Ransomware groups posted 7,655 victim claims to public leak sites from March 2025 to March 2026, with Qilin being the most active group posting 1,179 claims across 74 countries. The top 5 groups accounted for 40% of the claims, and the remaining 124 groups collectively posted 4,628 claims, suggesting that disrupting any single group is unlikely to reduce the overall total significantly.

Ordinary Lab Gloves May Have Skewed Microplastic Data

https://lede-admin.nautil.us/wp-content/uploads/sites/70/2026/03/Currie_HERO_009052.png?resize=2880%2C1920
Scientists researching microplastics may have skewed data by wearing gloves that shed particles mimicking microplastics. Clean-room gloves are a safer option, with 100 false positives per millimeter squared, compared to 2,000 from other gloves.

Ask HN: Distributed data centers in our basements

The idea of using home basements as mini data centers to reduce energy consumption and increase efficiency is unrealistic due to various technical, security, and regulatory challenges. However, it could be feasible for personal use or small-scale services, especially with advancements in hardware and software security, and if bandwidth and connectivity issues can be resolved.

Claude Code full source code leaked on NPM

https://opengraph.githubassets.com/92000bd2198251a1b05324a790c7ac1451a5ed0c868e546da433e8a6ebd876ba/chatgptprojects/claude-code
This repository extracts and preserves the original TypeScript source code of Anthropic's Claude Code CLI tool from its npm package. It unpacks the source map to make the code easier to read and reference.

Scotty: A beautiful SSH task runner

https://raw.githubusercontent.com/spatie/scotty/refs/heads/main/docs/images/scotty-run-deploy.jpg
Scotty is a new SSH task runner that lets you define deploy scripts and run them from your terminal with real-time output. It supports both Blade and plain bash formats, and offers features like pause and pretend modes.

Securing Elliptic Curve Cryptocurrencies Against Quantum Vulnerabilities [pdf]

Researchers from Google Quantum AI and other institutions have published a whitepaper warning of the potential risks of quantum computers to blockchain security, particularly in cryptocurrencies that rely on Elliptic Curve Discrete Logarithm Problem (ECDLP) cryptography. They estimate that a quantum computer with fewer than half a million physical qubits could break ECDLP-based cryptography ...

Closed Source AI = Neofeudalism

Good people in AI labs are driven by a desire to contribute to science, not power, but institutions push towards concentration of power and control. A free technical order prioritizes safety, openness, and local control to prevent a single entity from curating the future of AI.

Super Micro Computer Investors Look for Exits

https://catenaa.com/wp-content/uploads/2025/11/Baidu-Unveils-Two-New-AI-Chips-To-Replace-US-Chips-1024x683.webp
Super Micro Computer faces investor exodus due to recent indictment of its co-founder and past financial issues. Despite soaring sales, the company's stock price has dropped 63% since July 2025.

In Expanding de Sitter Space, Quantum Mechanics Gets More Elusive

https://www.quantamagazine.org/wp-content/uploads/2026/03/Shalma-Wegsman-alt-profile.webp
Physicists are struggling to understand the quantum world in an expanding universe, particularly in de Sitter space where space expands exponentially. They are trying to learn from black holes to make sense of quantum mechanics in de Sitter space.

Objections to systemd age-attestation changes go overboard

A pull request to add a field to store a user's birth date in systemd's JSON user records has sparked a hostile response from some community members, with some receiving death threats and doxxing. The change aims to facilitate compliance with age-attestation and -verification laws, but critics argue it's a step towards surveillance and should be targeted at the people pushing for these laws ...

Ask HN: Academic study on AI's impact on software development – want to join?

Researchers at New York University and City, University of London are conducting a study on AI's impact on software development. They are seeking US-based developers to share their experiences and perspectives on using AI tools in their day-to-day work via a 45-60 minute Zoom interview.

JSSE: A JavaScript Engine Built by an Agent

https://p.ocmatos.com/img/2026/03/jsse-agent-dreaming.png
The author built a JavaScript engine called JSSE from scratch in six weeks using a single agent, Claude Code, without writing any Rust code, and it passed 100% of test262 non-staging tests. The project demonstrated the power of agentic coding and the importance of a good plan, and it laid the groundwork for future improvements in software production.

Forth VM and compiler written in C++ and Scryer Prolog

https://opengraph.githubassets.com/325162b95cbfed114af5c4c3939af7aa9c0bcb642a1336b65cea4440849ac9ab/no382001/forth-vm
Forth VM and statically-typed s-expression compiler, written in C++ and Scryer Prolog - no382001/forth-vm

Show HN: PhAIL – Real-robot benchmark for AI models

https://phail.ai/phail-static/phail-icon.png
Five leading models. One commercial task. Production metrics.

Show HN: Pardus Browser- a browser for AI agents without Chromium

https://opengraph.githubassets.com/968bbaa0b5d8db76fc20eb99c2ba65d3a67ee5f53b6c893b8d733dc54a716a35/JasonHonKL/PardusBrowser
Pardus-browser is a headless browser for AI agents that fetches URLs, parses HTML, and outputs a clean semantic tree in milliseconds. It supports various formats, including Markdown, tree, and JSON, with options for custom headers, JavaScript execution, and verbose logging.

Show HN: My open-world voxel game with a magic system, playable in the browser

https://kouh.me/static/wildmagic/screenshot2.jpg
🏠 Start in a quiet neighborhood. Practice spells in your basement. Try not to blow up the garage. βš” Head into the wilderness. Find ruins, underwater caves, and rival wizards who want you dead.

Show HN: Cerno – CAPTCHA that targets LLM reasoning, not human biology

https://cerno.sh/og.png
01 Proof of work SHA-256 hash prefix, 14–24 bits. Adaptive difficulty based on client signals. 03 Motor-control analysis 12 behavioral features (7 public + 5 secret, server-only) extracted from raw pointer events. Scored against per-maze baselines. 05 Signature binding ECDSA P-256 ephemeral keypair. Public key bound at challenge issuance, verified on submission.

Project Mario: the inside story of DeepMind

https://colossus.com/wp-content/uploads/2026/03/ColossusMagazine_AIgovernance_eshakespeare_WEB-horizontal_FINALv1-scaled.jpg
Demis Hassabis and Mustafa Suleyman sought to create a governance structure for AI at DeepMind, but faced resistance from Google. They eventually secured a $1 billion investment from Reid Hoffman to pursue a spin-out, but negotiations with Google stalled.

Show HN: Raincast – Describe an app, get a desktop app (open source)

https://raw.githubusercontent.com/tihiera/raincast/main/src-tauri/icons/128x128%402x.png
Raincast is a native desktop app generator that builds real, shippable applications from natural language descriptions. It uses AI to create fully functional apps with UI, backend commands, file system access, and system integration in various layouts.

Show HN: Hyprmoncfg – Terminal-based monitor config manager for Hyprland

https://paolino.me/images/hyprmoncfg-demo.gif
hyprmoncfg is a TUI tool for configuring Hyprland monitors with spatial layout and workspace planning features. It's a lightweight, portable, and SSH-friendly alternative to other tools with a focus on reliability and ease of use.