Inside the npm supply-chain attack that shipped to 40,000 projects
A single compromised maintainer token, a post-install script, and eleven days before anyone noticed. Here is the full timeline.
whoami
tail -f headlines.log
Most news sites re-package yesterday's press releases. This one doesn't — every post is capped at five minutes, opens with what actually changed, and tells you why it matters before it tells you what happened.
A single compromised maintainer token, a post-install script, and eleven days before anyone noticed. Here is the full timeline.
Median seed size is up, deal count is down 22%. What founders are actually being asked for at first meeting now.
We benchmarked six 2026 machines on the same Rust build. The gap is no longer theoretical.
Transparency obligations are live. If you ship a model or a wrapper into the EU, these are the ones with real fines attached.
Three teams moved off managed cloud this year. Two saved money, one regretted it. The difference was not technical.