<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ffemac</title><link>https://news.ycombinator.com/user?id=ffemac</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 03 Jun 2026 20:24:53 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ffemac" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ffemac in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>True, but security breach inside a sandbox/container can cause serious damage too(stealing your code/data/keys, spreading via your code/release etc).  And containers aren't for security anyway(e.g. Copy Fail breaching to host <a href="https://xint.io/blog/copy-fail-pod-to-host" rel="nofollow">https://xint.io/blog/copy-fail-pod-to-host</a>)</p>
]]></description><pubDate>Wed, 03 Jun 2026 14:00:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48384218</link><dc:creator>ffemac</dc:creator><comments>https://news.ycombinator.com/item?id=48384218</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48384218</guid></item><item><title><![CDATA[New comment by ffemac in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>> malicious-NPM-package-of-the-week<p>This is going to get worse and worse. I recently noticed AI harness (e.g. OpenCode) downloading random npm packages in the background and litter them everywhere in a few place in ~ and in your project dir, all without telling/asking you.<p>What's worse is that people don't seem to care even the devs.</p>
]]></description><pubDate>Wed, 03 Jun 2026 08:04:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48381254</link><dc:creator>ffemac</dc:creator><comments>https://news.ycombinator.com/item?id=48381254</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48381254</guid></item><item><title><![CDATA[New comment by ffemac in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>I looked into Zed because popular harness (OpenCode/KiloCode) just random downloads npm packages in the background and didn't tell you.  But then I found out reports of Zed doing the same.   Why we can't have nice things?</p>
]]></description><pubDate>Wed, 03 Jun 2026 07:57:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48381188</link><dc:creator>ffemac</dc:creator><comments>https://news.ycombinator.com/item?id=48381188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48381188</guid></item><item><title><![CDATA[New comment by ffemac in "Malicious npm packages detected across Red Hat Cloud Services"]]></title><description><![CDATA[
<p>No, it will stop working. The whole point of min age is letting someone else taste the food before you, so you are not poisoned. (except maybe scanners but they can't detect everything and the payloads will highly likely to remain dormant when it detected it's within a scanning env).<p>BTW it will only get much worse because popular AI coding harness (e.g. OpenCode/KiloCode) will just download random npm packages in the background without you knowing. And the devs don't care.</p>
]]></description><pubDate>Mon, 01 Jun 2026 21:30:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48362911</link><dc:creator>ffemac</dc:creator><comments>https://news.ycombinator.com/item?id=48362911</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48362911</guid></item><item><title><![CDATA[New comment by ffemac in "Malicious npm packages detected across Red Hat Cloud Services"]]></title><description><![CDATA[
<p>Exactly, popular AI coding harness (OpenCode/KiloCode) downloads random npm packages in the background without you knowing. What's worse is the devs don't care.</p>
]]></description><pubDate>Mon, 01 Jun 2026 21:21:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48362811</link><dc:creator>ffemac</dc:creator><comments>https://news.ycombinator.com/item?id=48362811</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48362811</guid></item><item><title><![CDATA[New comment by ffemac in "Malicious npm packages detected across Red Hat Cloud Services"]]></title><description><![CDATA[
<p>It will only get much worse because popular AI coding harness (OpenCode/KiloCode) will just download random npm packages in the background without you knowing. And the devs don't care.<p>Setting min age is useless if everyone is doing it. The whole point of setting min age is make someone else take the bait before you.</p>
]]></description><pubDate>Mon, 01 Jun 2026 21:18:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48362783</link><dc:creator>ffemac</dc:creator><comments>https://news.ycombinator.com/item?id=48362783</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48362783</guid></item></channel></rss>