Skip to content

Commit 8c79bf8

Browse files
authored
Merge pull request #148 from Dimi8146/patch-1
NPM Incident Addition
2 parents e7fda93 + d0f25ef commit 8c79bf8

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

_posts/2025-09-11-socratic-seminar-69.md

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,7 @@ https://github.com/bitcoinknots/bitcoin/releases/tag/v29.1.knots20250903
3535

3636
https://github.com/TABConf/bitcoinknobs
3737

38-
Bitcoin Knobs is a fork of Bitcoin Knots that takes flexibility a step further. Where others decide what is "safe" or "reasonable," we believe in maximum choice. If that means your node refuses to start, your wallet vanishes into the void, or your peers pretend you don't exist, at least the decision was yours.
39-
ody sane would touch. Some people call that dangerous. We call it feature-complete.
38+
Bitcoin Knobs is a fork of Bitcoin Knots that takes flexibility a step further. Where others decide what is "safe" or "reasonable," we believe in maximum choice. If that means your node refuses to start, your wallet vanishes into the void, or your peers pretend you don't exist, at least the decision was yours. Because freedom means being able to tune every setting, even the ones nobody sane would touch. Some people call that dangerous. We call it feature-complete.
4039

4140
## Nunchuk releases Miniscript + E2EE group wallets
4241

@@ -88,3 +87,10 @@ Utreexo BIP drafts published by @kcalvinalvinn, co-authored by @tdryja and David
8887
- BIP drafts: https://github.com/bitcoin/bips/pull/1923
8988
- Mail list post: https://groups.google.com/g/bitcoindev/c/W1lxBraKG_E
9089
- Utreexo is a proposed alternative to the UTXO set; more info at https://bitcoinops.org/en/topics/utreexo/
90+
91+
## NPM Malicious Packages Incident
92+
93+
https://x.com/P3b7_/status/1965094840959410230
94+
https://x.com/P3b7_/status/1965336272550899932
95+
96+
$66 stolen in widespread supply chain attack. The developer of a dozen high-impact javascript packages was phished and these packages turned malicious. The NPM security team cleaned up quick and internet-citizen reporting was early and widespread, minimizing impact.

0 commit comments

Comments
 (0)