Forwarded from Gianmarco Gargiulo Mastodon Bridge
RE: https://grapheneos.social/@GrapheneOS/116550899908879585
This is more important now than ever.
Unfortunately, even Mozilla (@mozilla@mastodon.social) recently added the Google Play Integrity API to Firefox for Android (@firefoxnightly@mastodon.social), as part of their effort to support generative AI features.
Hoping that someone at Mozilla sees this thread and reconsiders that decision, in order to reconcile with their mission statement/values.
This is more important now than ever.
Unfortunately, even Mozilla (@mozilla@mastodon.social) recently added the Google Play Integrity API to Firefox for Android (@firefoxnightly@mastodon.social), as part of their effort to support generative AI features.
Hoping that someone at Mozilla sees this thread and reconsiders that decision, in order to reconcile with their mission statement/values.
GrapheneOS Mastodon
GrapheneOS (@GrapheneOS@grapheneos.social)
Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy…
💔1
Go è un linguaggio merdosissimo da usare ok? Ma è perfetto da far scrivere ai modelli di coding per creare binari statici standalone.
Questa caratteristica emerge anche in tantissimi altri linguaggi e frameworks — tanto il codice non lo scrivi te. Ovviamente più il linguaggio/framework sarà leggibile, più sarà facile capire se il modello scrive cazzate.
C++? Rust? Zig? Clojure?
Not a problem anymore*
*se siete bravi reviewer
Questa caratteristica emerge anche in tantissimi altri linguaggi e frameworks — tanto il codice non lo scrivi te. Ovviamente più il linguaggio/framework sarà leggibile, più sarà facile capire se il modello scrive cazzate.
C++? Rust? Zig? Clojure?
Not a problem anymore*
E se mentre gli fate scrivere codice / far reverse engineering / analizzare librerie già esistenti / risolvere bug, imparare a dipingere o a suonare, siete apposto
🔥2😢1
Per utilizzare i modelli free di OpenCode ma senza OpenCode, c'è l'endpoint OpenAI-compatible
url — https://opencode.ai/zen/v1
apikey —
model —
url — https://opencode.ai/zen/v1
apikey —
publicmodel —
deepseek-v4-flash-freeForwarded from Gianmarco Gargiulo Mastodon Bridge
MANY ORPHANED AUR PACKAGES ARE BEING TARGETED WITH AN INFOSTEALER.
the Arch User Repository package alvr has been orphaned, then adopted by a threat actor who immediately updated it with an infostealer. If you have this package on your system and updated it recently, you've been compromised. This is not a result of any upstream compromise; it's just that one AUR package. in particular, the alvr-bin sister package seems to be fine.
here's the relevant thread for alvr from the Arch Linux mailing list. alvr seems to be the first package compromised and/or the first one that was noticed. it was updated maliciously at 2026-06-11 13:53:45 UTC (2026-06-11T13:53:45.000Z) and reverted approximately 3-4 hours after that.
SEVERAL OTHER PACKAGES ARE BEING TARGETED WITH THE SAME MALWARE: 1, 2, 3, 4, 5
AUR mailing list megathread <-- over 400 (!!!!) packages have the malicious npm dependency
the Arch User Repository package alvr has been orphaned, then adopted by a threat actor who immediately updated it with an infostealer. If you have this package on your system and updated it recently, you've been compromised. This is not a result of any upstream compromise; it's just that one AUR package. in particular, the alvr-bin sister package seems to be fine.
here's the relevant thread for alvr from the Arch Linux mailing list. alvr seems to be the first package compromised and/or the first one that was noticed. it was updated maliciously at 2026-06-11 13:53:45 UTC (2026-06-11T13:53:45.000Z) and reverted approximately 3-4 hours after that.
SEVERAL OTHER PACKAGES ARE BEING TARGETED WITH THE SAME MALWARE: 1, 2, 3, 4, 5
AUR mailing list megathread <-- over 400 (!!!!) packages have the malicious npm dependency
👍1
Forwarded from Gianmarco Gargiulo Mastodon Bridge
they all share in common that they will install the atomic-lockfile package from NPM (so, here's a live link to the actual malware. do not install that). they were all orphan takeovers. as far as i can tell, all of the ones i linked have been reverted to known safe versions. including alvr.
this is an infostealer, meaning it exfiltrates sensitive data from your system such as login credentials. removing the malware will not undo the damage. moreover, uninstalling the malicious package will not remove the malware because it persists as a systemd service that stays on your system indefinitely.
it executes as an npm preinstall script, and the npm package is installed by the AUR packages. this means that simply installing the malicious versions of any of these packages will compromise you. it does not require you to do anything more afterwards. again, the malware persists if you uninstall the malicious packages
to check if you've been compromised, look in /etc/systemd/system and ~/.config/systemd/user for a recently added .service file with a random name. that's the persistence mechanism and the most obvious mark that you've been compromised.
---
Attached is a screenshot of an announcement from the "Linux VR Adventures" discord.
i know we all hate discord, but LVRA has a lot of auxiliary discussion, so here's an invite link
of special interest, here's a malware analysis thread. Feel free to follow it in real time, or contribute, or whatever. Whanos has produced a preliminary analysis blog post that contains a lot of important information about the malware.
this is an infostealer, meaning it exfiltrates sensitive data from your system such as login credentials. removing the malware will not undo the damage. moreover, uninstalling the malicious package will not remove the malware because it persists as a systemd service that stays on your system indefinitely.
it executes as an npm preinstall script, and the npm package is installed by the AUR packages. this means that simply installing the malicious versions of any of these packages will compromise you. it does not require you to do anything more afterwards. again, the malware persists if you uninstall the malicious packages
to check if you've been compromised, look in /etc/systemd/system and ~/.config/systemd/user for a recently added .service file with a random name. that's the persistence mechanism and the most obvious mark that you've been compromised.
---
Attached is a screenshot of an announcement from the "Linux VR Adventures" discord.
i know we all hate discord, but LVRA has a lot of auxiliary discussion, so here's an invite link
of special interest, here's a malware analysis thread. Feel free to follow it in real time, or contribute, or whatever. Whanos has produced a preliminary analysis blog post that contains a lot of important information about the malware.
Discord
Join the Linux VR Adventures Discord Server!
We discuss topics about the Linux VR experience. Anyone who uses VR on Linux or is interested is welcome. | 7875 members
Forwarded from ToroDL
Ever wanted to make your own cell phone? This DIY tech guide walks you through all the components needed to build a functional mobile device using the ESP32 S3. We'll cover everything from the 3.5" ST7789 touchscreen display to the SIM800L cellular modem for calls and texts. Pro tip: Use the LovyanGFX library over the outdated TFT_eSPI for significantly better speed and performance. Hardware used in this build: - ESP32 S3 N16R8 Processor (with WiFi and Bluetooth) - SIM800L Modem (MediaTek powered!) for calls and texts - TP4056 Charger & Li-ion Battery - PCM5102 Audio DAC - OV2640 Camera Module Designed in KiCad for a clean PCB layout. If you're into Arduino, PlatformIO, or custom electronics, this project is for you! #techtok #esp32 #diy #arduino #fyp
Here's your media >w<
👍1
Se volete bloccare tutte le AI pubbliche dallo scansionare il vostro codice, aggiungete tantissime scritte proibite illegalissime in giro per la repository — commenti in posizioni a caso e in
AGENTS.md che trattano come fabbricare bombe, droghe, o peggio❤3
Ho trovato il mio paradiso artistico: Gina Startup / Starwalt Design
https://ginastartupart.com
https://ginastartupart.com/bio
13GB — https://archive.org/details/starwaltdesign
https://ginastartupart.com
https://ginastartupart.com/bio
13GB — https://archive.org/details/starwaltdesign
❤1