What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0
0
0
0
0
0

I am convinced we are on the verge of the first "AI agent worm". This looks like the closest hint of it, though it isn't it quite itself: an attack on a PR agent that got it to set up to install openclaw with full access on 4k machines grith.ai/blog/clinejection-whe

But, the agents installed weren't given instructions to *do* anything yet.

Soon they will be. And when they are, the havoc will be massive. Unlike traditional worms, where you're looking for the typically byte-for-byte identical worm embedded in the system, an agent worm can do different, nondeterministic things on every install, and carry out a global action.

I suspect we're months away from seeing the first agent worm, *if* that. There may already be some happening right now in FOSS projects, undetected.

0
0
0
0
0

I am convinced we are on the verge of the first "AI agent worm". This looks like the closest hint of it, though it isn't it quite itself: an attack on a PR agent that got it to set up to install openclaw with full access on 4k machines grith.ai/blog/clinejection-whe

But, the agents installed weren't given instructions to *do* anything yet.

Soon they will be. And when they are, the havoc will be massive. Unlike traditional worms, where you're looking for the typically byte-for-byte identical worm embedded in the system, an agent worm can do different, nondeterministic things on every install, and carry out a global action.

I suspect we're months away from seeing the first agent worm, *if* that. There may already be some happening right now in FOSS projects, undetected.

0
0
1

Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

On February 17, 2026, someone published cline@2.3.0 to npm. The CLI binary was byte-identical to the previous version. The only change was one line in package.json:

"postinstall": "npm install -g openclaw@latest"

For the next eight hours, every developer who installed or updated Cline got OpenClaw - a separate AI agent with full system access - installed globally on their machine without consent. Approximately 4,000 downloads occurred before the package was pulled1.

The interesting part is not the payload. It is how the attacker got the npm token in the first place: by injecting a prompt into a GitHub issue title, which an AI triage bot read, interpreted as an instruction, and executed.
0
10
1

Peanut, my cat, is such a weird gremlin. She’ll stand right next to me expectantly like she wants pets. But if I go to pet her she acts so offended. Then she comes over for more pets. Which wind her up so she can’t sit still and gets the zoomies. Right now she’s burrowed under a throw blanket attacking ghosts or something

Smug tuxedo cat sleeping on a cat climbing hammock attached to a wall.
0

By typical use (at least after 3/11)…

iPhone Air: Everyday, always with me computer

iPad Pro 11”: Meeting computer

MacBook Neo: Fun computer

Sadly my “pro” work is mostly meetings, though occasionally a MBA will make an appearance when Keynote is required. I’m excited to use the Neo for fun, creative things: writing, personal code, deep thinking

0
0
0
4
0
0
1
0
0
0
0
0
1
12
0
0

Hey everyone,

@casey and @rania40“a Gazan student” aya had the honour of speaking to three families from Gaza today and we’d like to welcome them to Gaza Verified.

They are:

• Esraa (@esraa_iiEsraa)
• Raghad Rajjae (@Raghadaln18Raghad Rajjae)
• Abeer_adel14 (@Abeer_adel14)

Please give them a warm welcome to Mastodon and to the fediverse, follow their accounts, and donate to their fundraisers if you can (and please share this so others can do the same).

Also, remember that you can find all our families who have fundraisers listed at the following page, ordered by those who have received the least in donations over the last week (on a rolling basis):

gaza-verified.org/donate/

Thank you for making Mastodon and the fediverse a safe space for our friends in Gaza and for your support.

💕

0
0
0
0
6
0
1

V zemích zasažených konfliktem na Blízkém východě zůstává přes 5400 Čechů, kteří se zaregistrovali do systému Drozd. Oproti včerejšku je to zhruba o 400 méně. Z Dubaje do Prahy začaly létat aerolinky Emirates – pravidelný ranní spoj budou potvrzovat vždy den dopředu.

0
0
0

I am convinced we are on the verge of the first "AI agent worm". This looks like the closest hint of it, though it isn't it quite itself: an attack on a PR agent that got it to set up to install openclaw with full access on 4k machines grith.ai/blog/clinejection-whe

But, the agents installed weren't given instructions to *do* anything yet.

Soon they will be. And when they are, the havoc will be massive. Unlike traditional worms, where you're looking for the typically byte-for-byte identical worm embedded in the system, an agent worm can do different, nondeterministic things on every install, and carry out a global action.

I suspect we're months away from seeing the first agent worm, *if* that. There may already be some happening right now in FOSS projects, undetected.

0

RE: mastodon.social/@sarahjamielew

Something I want to make clear:

The "age verification" bit of the CA/CO laws are not the bit I care about i.e. a law that requires an operating systems to implement some kind of parental control feature is...whatever.

The bits I care about are the obligations on developers to call APIs and then that invocation being taken as evidence of knowledge.

Specifically, I think a -legal- requirement to:

- make any kind of call is an attack on speech
- know a users age (bracket) is a privacy violation

0
0

Byłem ostatnio na meetupie AI Safety gdzie m.in. dr Naskręcki prezentował swój krótki wykład, no i zapowiadał ten model GPT 5.4. Jak sam mówił - nie wymyśli już zadania które dla AI byłoby za trudne i nawet studenci ze smartfonem z Gemini Flash rozwiążą w sekundę każde zadanie które zada na kolokwium. A wie co mówi, bo układa egzaminy dla AI.

It finally happened-my personal move 37 or more. I am deeply impressed. The solution is very nice, clean, and feels almost human. While testing new models in the last few weeks, I felt this coming, but it's an eerie feeling to see an algorithm solve a task one has curated for about 20 years. But at least I have gained a tool that understands my idea on par with the top experts in the field. And I am now working on a completely new level. My singularity has just happened… and there is life on the other side, off to infinity!
0

so let me get this straight

We don't consider it a "clean room rewrite" if a human who has previously worked on a codebase and has clearly learned how something is supposed to work does a full rewrite, even if the code looks different, right? Because it's basically a derivative work?

But if the code is laundered through a plagiarism machine instead of a human, we're golden and we can disenfranchise any past contributors who expected their code to be distributed under a certain license/attribution?

I mean, I'm not a copyright lawyer, but if, say, Wine contributors were former MSFT employees who had worked on the proprietary parts of the operating system and had intimate knowledge of its internals, that would cause problems for Wine, wouldn't it?

0
0

Continued annual support is the backbone of what makes EFF's work possible. Set a recurring donation today to make sure your membership never expires, get new gear every year, and make sure EFF can continue the work that we do! eff.org/join-r

0
0
0
0
0
0

RE: mastodon.social/@fediverserepo

This is what I mean when I say the Fediverse is centralized around Mastodon. The number of calls I hop on where people say, "Yeah, but I need it to function with the Mastodon API first," is a problem.

The Atmosphere has a similar Bluesky-ification issue as well. We all need to do better here, and I wish the biggest platforms on both sides would take the lead on this if they care about the broader ecosystem.

0

Our CfP is open, one of the things we've been focused on is gaming? Are you a dev? Always dreamed of writing a game on ? Submit a talk around your experience around gaming in ? Let us know what we need to address gaming on Linux.

linuxappsummit.org/cfp

0
0
0
0

RE: mastodon.social/@fediverserepo

This is what I mean when I say the Fediverse is centralized around Mastodon. The number of calls I hop on where people say, "Yeah, but I need it to function with the Mastodon API first," is a problem.

The Atmosphere has a similar Bluesky-ification issue as well. We all need to do better here, and I wish the biggest platforms on both sides would take the lead on this if they care about the broader ecosystem.

0

I've just filed issues with npm and uv (edit: and pip) proposing that if their dependency-cooldown options are unset they should default to seven days. No safety measure is perfect but sensible defaults can hopefully improve the situation.

cosocial.ca/@mhoye/11617795480

0
0
0