Live data from Hacker News

Viewing profile — singulasar

singulasar

HN member
Joined
Mon, Sep 08, 2025, 4:14 PM UTC
HN karma
12
Public activity
17 items

About singulasar

No profile information was provided.

Recent public activity

  1. comment
    Comment #47355788

    https://github.com/betterleaks/betterleaks

  2. comment
    Comment #45361038

    Let's hope the defunding of medical research can stop so this can become true

  3. comment
    Comment #45292071

    The chalk/debug one https://www.aikido.dev/blog/npm-debug-and-chalk-packages-com... I believe socket also found it this way just a bit later. The dev later said that Charlie notify…

  4. comment
  5. comment
    Comment #45287882

    Hmm, sure, I can agree that the position is extremist, I still don't agree that 1 (or some) extremist positions makes the current people in power extremist. Or at least, maybe they…

  6. comment
    Comment #45287559

    Not really, app sec companies scan npm constantly for updated packages to check for malware. Many attacks get caught that way. e.g. the debug + chalk supply chain attack was caught…

  7. comment
    Comment #45287537

    Again, I disagree, I wouldn't call it extremist. It's vile and wrong, but people all over the political spectrum are in favour of this. there's a difference between something being…

  8. comment
  9. comment
    Comment #45275580

    There's multiple security firms by now that constantly scan updated npm packages for malware. Obviously those companies can only do this after a new package has been published. Npm…

  10. comment
    Comment #45274981

    or maybe let's not? their actions are clearly not extremist, absolutely not perfect and not always equally democratic, but not extremist or violent like the actual extremists...

  11. comment
    Comment #45274026

    on the other hand, the previous supply chain attack was found by automated tech. Also, if MS would be so kind as to just run similar scans at the time a package is updated instead …

  12. comment
    Comment #45273990

    Yes to the you guys can detect it in my codebase, but it's generally not required for someone to report a compromised package, we do also discover them ourselves quite fast due to …

  13. comment
    Comment #45261116

    I'm so sick of people saying this. If you use js for any non-tiny project, you'll have a bunch of packages. Due to how modules work in js, you'll have many, many sub dependencies. …

  14. comment
    Comment #45213269

    https://circleid.com/posts/chat-control-proposal-advances-de... https://fightchatcontrol.eu/ https://european-pirateparty.eu/chatcontrol-eu-ministers-wan...

  15. comment
    Comment #45185239

    unphishable 2fa would have prevented this specific case tho... what are you talking about?

  16. comment
    Comment #45185106

    the company that first found this vulnerability also has a tool for this https://www.npmjs.com/package/@aikidosec/safe-chain

  17. comment
    Comment #45185080

    I think it's quite good, there's a sense of urgency, but it's also not "immediately change it!" they gave more than a day, and stated that it would be a temporary lock. Feel like t…