Axios compromised on NPM – Malicious versions drop remote access trojan

https://cdn.prod.website-files.com/673b71f0790aabf30bd30bf8/69cb2363fdc3f8e8fa0460a5_blog-cover-image.png
StepSecurity identified malicious versions of the axios HTTP client library published to npm, [email protected] and [email protected], which inject a remote access trojan (RAT) dropper. Developers who installed these versions should rotate all secrets and credentials, check network logs, and downgrade to safe versions, and StepSecurity provides end-to-end npm supply chain security across three pillars: ...

Open source CAD in the browser (Solvespace)

SolveSpace has a web version that runs in the browser with some speed penalty and bugs. It's experimental and can be hosted locally like static web content.

GitHub Monaspace Case Study

https://lettermatic.com/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fblwjvcya%2Fproduction%2F095a628b998a2e81d05e90e387b87b9ca3eeac08-1733x1229.png&w=1920&q=75
GitHub and Lettermatic collaborated to create Monaspace, a superfamily of five interchangeable typefaces for code editors. Monaspace offers high personalization and accessibility features, including Texture Healing, which improves legibility in monospace typefaces.

Cohere Transcribe: Speech Recognition

https://cdn.sanity.io/images/rjtqmwfu/web3-prod/8054a4393c0b87afbde5d6d4de810d08d2c4db26-3140x1420.png?auto=format&fit=max&q=90&w=1570
Cohere Transcribe is an open-source automatic speech recognition model that achieves state-of-the-art accuracy with a low word error rate of 5.42%. It is available for download and can be used for real-world transcription tasks across 14 languages.

Oracle slashes 30k jobs

Oracle laid off 20,000-30,000 employees, roughly 18% of its workforce, in a single email with no advance notice. The cuts are tied to Oracle's aggressive expansion into AI infrastructure, freeing up $8-10 billion in cash flow.

Ollama is now powered by MLX on Apple Silicon in preview

https://files.ollama.com/ollama_mlx.png
Ollama now runs faster on Apple silicon with MLX framework, leveraging GPU Neural Accelerators for speedup. Ollama 0.19 sees 1851 token/s prefill and 134 token/s decode with improved memory efficiency and model accuracy.

A Love Letter to 'Girl Games'

https://aftermath.site/content/images/2026/03/Screenshot-2026-03-23-at-12.09.12-PM.png
The author reminisces about childhood games like Pixie Hollow and Bratz: Rock Angelz, now lost due to cultural erasure of feminine games. FEMICOM Museum founder Rachel Weil aims to preserve and celebrate games targeted toward young girls.

Artemis II is not safe to fly

https://idlewords.com/images/oig_heat_shield.jpg
NASA's Orion spacecraft has a defective heat shield that could kill the crew on Artemis II due to spalling, impact from heat shield fragments, and bolt erosion. Despite this, NASA is planning to fly the mission with a crew, citing a change in the re-entry trajectory and a new heat shield design for future missions.

Italy blocks US use of Sicily air base for Middle East war

https://www.politico.eu/cdn-cgi/image/width=1160,height=772,quality=80,onerror=redirect,format=auto/wp-content/uploads/2026/03/31/GettyImages-1394407486-scaled.jpg
EU countries consider alternatives to Hungary if Orbán wins, while progressive voters abandon center-left parties in Europe. Transatlantic tensions rise as the US rejects a Russian proposal, affecting Italy's leader and other European nations.

Claude Code's source code has been leaked via a map file in their NPM registry

Something went wrong, but don’t fret — let’s give it another shot. Some privacy related extensions may cause issues on x.com. Please disable them and try again.

Combinators

https://tinyapl.rubenverg.com/combinators/same.svg
Combinators are functions that refer to their arguments without modifying them. They are often represented by bird names in APL, such as Kestrel and Cardinal.

Audio tapes reveal mass rule-breaking in Milgram's obedience experiments

https://sp-ao.shortpixel.ai/client/to_webp,q_glossy,ret_img,w_750,h_375/https://www.psypost.org/wp-content/uploads/2024/01/stanley-milgram-experiment-1-750x375.jpg
Researchers analyzed audio recordings from the Milgram experiment and found that obedient participants broke the rules of the study most of the time, often ignoring the scientific procedure. This suggests that the laboratory environment was one of unauthorized violence, rather than a legitimate scientific study.

RubyGems Fracture Incident Report

https://rubycentral.org/assets/images/gem-logo--badge.svg?v=f673e7d640
Ruby Central's Open Source Committee faced a crisis in September 2025 known as the "RubyGems Fracture" due to a poorly communicated process to offboard two engineers, André Arko and Samuel Giddens, from the RubyGems.org service. The incident led to the removal of paid contributors and highlighted the need for better policies, procedures, and communication in managing access and offboarding in ...

Tell HN: Chrome says "Suspicious Download" when trying to download yt-dlp

Google's browser warns of a "Suspicious Download" for yt-dlp, a tool to download files from Google's servers. This is seen as browser monopoly abuse and misleading people, as Chrome also downloads files from various servers.

Dot – A Siri Replacement learns skills through Apple Shortcuts

https://is1-ssl.mzstatic.com/image/thumb/PurpleSource211/v4/11/e1/3a/11e13a18-8d11-e3bb-7238-c474a87566fe/Placeholder.mill/1200x630wa.jpg
Dot is a powerful personal AI assistant built for your iPhone. Tell it what you need and it gets it done — securely right on your phone. Dot is special because it can learn from you and for you. Need something done in one of your apps? Dot will create a skill to get it done. What can Dot do? - Control your smart home — turn on the lights, lock the front door, adjust the thermostat - Manage ...

Good Code Will Still Win

https://www.greptile.com/blog/ai-slopware-future/unnamed.png
A couple of years ago, "slop" became the popular shorthand for unwanted, mindlessly generated AI content flooding the internet including images, text, and spam. Simon Willison helped popularize the term, though it had been circulating in engineering communities in the years prior. At Greptile, we spend a lot of time thinking about questions like: Is slop the future? Are programming ...

What major works of literature were written after age of 85? 75? 65?

https://statmodeling.stat.columbia.edu/wp-content/uploads/2026/03/author_age_at_publication-1024x614.png
The author discussed major works published by authors over 85, citing Sophocles' Philoctetes and Goethe's Faust, but found few notable works by authors over 80. A list of notable works by authors over 65 includes V. Hugo's Ninety-three, T. Mann's Doctor Faustus, and J. Saramago's Blindness.

Multiple Sclerosis

I was recently diagnosed with Relapsing-Remitting Multiple Sclerosis after experiencing numbness and tingling in my arm and torso. I'm starting treatment to manage symptoms and slow disease progression.

Microsoft: Copilot is for entertainment purposes only

https://cdn-dynmedia-1.microsoft.com/is/image/microsoftcorp/MSFT-Learn-Hero-Alt2_tbmnl_en-us?scl=1
You agree to these terms by using Copilot, which includes rules for using the service, protecting others, and respecting Microsoft's rights. By using Copilot, you grant Microsoft permission to use your content and agree to their terms, including the Microsoft Services Agreement and the Microsoft Privacy Statement.

Show HN: Loreline, narrative language transpiled via Haxe: C++/C#/JS/Java/Py/Lua

https://loreline.app/static/img/vscode-screenshot.png
Loreline is a narrative language that uses Haxe for transpilation to multiple platforms, allowing it to run everywhere. It has a lexer, parser, and interpreter that transform source text into executable code, with a focus on performance and simplicity.

Fedware: Government apps that spy harder than the apps they ban

https://www.sambent.com/content/images/size/w160/2025/07/370-----Photos-1.png
The US government's mobile apps, including the White House app, request excessive permissions and embed trackers, violating users' privacy. These apps, part of a surveillance apparatus, collect sensitive data that feeds into ICE raids and warrantless location tracking.

Show HN: Hyprmoncfg – Terminal-based monitor config manager for Hyprland

https://paolino.me/images/hyprmoncfg-demo.gif
Configuring monitors in Hyprland means writing monitor= lines by hand. A 4K display at 1.33x scale is effectively 2880x1620 pixels, so the monitor next to it needs to start at x=2880. Vertically centering a 1080p panel against it means doing division in your head to get the y-offset right. You reload, you’re off by 40 pixels, you edit, you reload again. There’s no visual feedback until after ...

Universal Claude.md – cut Claude output tokens

https://opengraph.githubassets.com/51e61dfbcd98b9faca0cb7e47d57dfdbf9b19326ffa23c3c1c377eea914ef093/drona23/claude-token-efficient
A CLAUDE.md file reduces Claude output verbosity by ~63% without code changes, targeting sycophancy, verbosity, and formatting noise. It's most beneficial for high-output use cases, and users can customize it to target specific failure modes and compose multiple files for different project types.

Google's 200M-parameter time-series foundation model with 16k context

https://opengraph.githubassets.com/3a715ab5ed97409698fa19e1f50846332c191dbd18b04dbc7566243837cc8897/google-research/timesfm
TimesFM is a pretrained time-series model by Google Research for forecasting. It can be installed via pip and used for point and quantile forecasting.

Project Mario: the inside story of DeepMind

https://colossus.com/wp-content/uploads/2026/03/ColossusMagazine_AIgovernance_eshakespeare_WEB-horizontal_FINALv1-scaled.jpg
The following is an exclusive excerpt adapted from the author’s new book, THE INFINITY MACHINE: Demis Hassabis, DeepMind, and the Quest for Superintelligence, out today. In the autumn of 2015, Mustafa Suleyman embarked on a grand experiment in making AI good for society. Together with Demis Hassabis, the senior co-founder of the London-based artificial intelligence lab DeepMind, he began an ...

RamAIn (YC W26) Is Hiring

https://bookface-images.s3.amazonaws.com/small_logos/9fe951afa5872a811734029111550a11062d931e.png
RamAIn builds AI agents for enterprise work, automating repetitive tasks 10x faster and more reliably than humans. We're hiring a Founding AI/ML researcher to design and deploy agents that reason, plan, and execute complex workflows autonomously.

Do your own writing

LLMs can undermine authenticity and credibility by generating writing that lacks thought and understanding. Effective writing requires human thoughtfulness and effort to establish credibility and increase understanding.

Good CTE, Bad CTE

https://boringsql.com/og-images/good-cte-bad-cte-og.jpg
CTEs are now inlined by default in PostgreSQL 12, allowing the planner to apply normal optimisations. Materialization is used when a CTE is referenced multiple times or contains side effects.

7,655 Ransomware Claims in One Year: Group, Sector, and Country Breakdown

https://ciphercue.com/img/og-card.png
Ransomware groups posted 7,655 victim claims to public leak sites from March 2025 to March 2026, with Qilin being the most active group posting 1,179 claims across 74 countries. The top 5 groups accounted for 40% of the claims, and the remaining 124 groups collectively posted 4,628 claims, suggesting that disrupting any single group is unlikely to reduce the overall total significantly.

GitHub backs down, kills Copilot pull-request ads after backlash

https://regmedia.co.uk/2024/05/21/github1_shutterstock.jpg
GitHub removed Copilot's ability to insert ads into pull requests after backlash from developers. The feature was disabled after users complained of unwanted ads in their pull requests.