search
NPM
Trends
- 1ChainDrop attack poisons npm packages via hijacked maintainer account●ChainDrop: attackers hijacked a maintainer's GitHub account and shipped poisoned npm releases with valid provenance. 400
Security researchers are warning about a supply chain attack dubbed ChainDrop, in which attackers took over a package maintainer's GitHub account and published malicious npm releases carrying valid cryptographic provenance. The compromised releases reportedly touched around 400 packages with an estimated two billion weekly downloads. Commentators say the attack shows that provenance attestation works technically but cannot protect against a trusted account being compromised in the first place.
Repos
- earendil-works/pi AI agent toolkit: unified LLM API, agent loop, TUI, coding agent CLI
- anthropics/claude-code Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster
- affaan-m/ECC The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development f
- gatewai-dev/gitframes Code-first video, rendered natively on WebGPU.
- pablostanley/yoinks yoink any video from your terminal. no shady ads.
- wy-coliney/jev-browser-use 5–10x faster browser operations: Jev clicks, Codex thinks and verifies. Built at EZCollegeApp.
- tamaratran/fast-jev-compaction Claude Code plugin that replaces the compaction summary with Jev decisions: every tool call and result is scored in one
- Parcha-ai/agentrun The Agentrun Workflow DSL
- WordPress/wordpress-develop WordPress Develop, Git-ified. Synced from git://develop.git.wordpress.org/, including branches and tags! This repository