Another NPM supply chain attack, this time it affects packages with around 2 billion weekly downloads total.
Looks like it tries to intercept and change crypto transactions.
This is why I dislike "supply chain languages" like JavaScript, Go, Rust, Ruby.
With them it's always "when", not "if".

chesheer
Post
-
Another NPM supply chain attack, this time it affects packages with around 2 billion weekly downloads total. -
I've already seen a video ad on a social commerce platform - Facebook - twice now.@stefano I constantly see the flood of these Temu videos on Youtube in Kazakhstan. They're all localized in Russian and Kazakh language.
Youtube actually is ridden with these scam ads. For example, when my parents open Youtube app, they see huge ad right on top of the feed. It often says that their PDF reader is compromised and they need to install an update ASAP. They're wise enough to not tap on it, but I wonder how many people do.
Google doesn't care.
It wasn't always like that. I worked with Google AdSense and Adwords back in 2010's, and Google instantly banned ads even if the phone number on your site mismatched with phone number in your ad.
Looks like now you can do whatever you want. -
I saw something disturbing this morning.@stefano This is true. Quite popular fraud scheme in my country (and actually post-Soviet space). So they collect enough samples of your voice to train AI, and then call your relatives asking to transfer money somewhere ASAP. That's one of the schemes.
-
For years you tell yourself: "I'm better than this".For years you tell yourself: "I'm better than this".
You try to convince yourself you don't need it.
Countless people live happily without it.
Not everyone needs to go this way.
You push these thoughts somewhere deep inside.
You just want to follow your dreams, you don't want to be bogged down in all this.
You look for an easy way out.
But the day of reckoning comes, and you finally submit to realization: "I gotta learn elisp". -
Lol, looks like the mastodon.bsd.cafe answers on 80 port faster than Yandex@evgandr I don't know why, but pings to mastodon.bsd.cafe and ya.ru give me equal results.
Despite the fact I'm in Kazakhstan, and bsd.cafe is much, much further away from me than ya.ru.
Also mastodon.bsd.cafe is 14 hops away via tracepath, ya.ru — tracepath just stops at 30 ("too many hops"). -
So I wrote some thoughts about why I don't trust privacy services like email, VPN, cloud services and so on.So I wrote some thoughts about why I don't trust privacy services like email, VPN, cloud services and so on.
https://iyer.ru/2025/08/30/why-i-don-t-trust-so-called-privacy-services/