Skip to content

Blog

Articles about AI, research, product management, and working with technology.

Axios supply chain attack: why the advice going around only checks macOS

The popular check-yourself commands for the axios npm compromise only cover macOS. Here is the full technical breakdown and verification steps for all three platforms.

securitynpmsupply-chain

Claude Code source has been available for 13 months, and nothing happened — why?

The full source code of Claude Code has been in the npm package since February 2025. Researchers extracted the roadmap, prompts, and hidden features — yet the product keeps growing.

ai-toolssecurityopen-source