A Pi extension that integrates Codex (ChatGPT) connectors—GitHub, Gmail, Google Calendar, Drive, Slack, Linear, Figma—into Pi models through a unified interface. Users install via npm, manage write approvals through environment variables, and access connector tools without exposing individual schemas to the model.
Bun-install is a CLI tool that installs commands from local workspaces or NPM packages into Bun's global package store, with support for command selection, dependency resolution, and Bun runtime override via shebang rewriting.
Paper is a local CLI tool designed to improve AI-assisted debugging by capturing errors into incident reports and providing agents with structured debugging context, eliminating inefficient debugging loops. The tool operates entirely locally without external API calls or third-party dependencies.
Frappe UI 1.0 has been released after four years of development, featuring 100+ components, dark mode, and AI readiness as a unified toolkit for building Frappe frontends. The major version stabilizes the API across 25+ dependent apps by standardizing inconsistent component naming and behavior, reducing 727 props to 188 unique names.
Nine npm packages published by user dirtyblanket on September 29, 2026, contain a self-spreading Linux worm that impersonates Express and React frameworks. The worm installs a backdoor, propagates via SSH keys and npm tokens, and uses the Wayback Machine to evade detection.
Nine malicious npm packages published by the dirtyblanket account on September 29, 2026, distribute a self-propagating Linux worm that installs a backdoor, steals SSH keys and npm tokens, and spreads via compromised machines to AUR packages and new npm versions. The worm uses a preinstall hook to download and execute a payload through the Internet Archive Wayback Machine, evading allowlists and version pinning.
MacUp is a macOS menu bar application that centralizes updates for multiple CLI package managers including Homebrew, npm, pip, and Cargo. It displays outdated packages with release dates and security information, allowing users to update them with a single click while respecting a minimum age period for stability.
A developer-focused platform aggregating security advisories, service outages, and releases. Recent critical vulnerabilities include XSS bypasses in SunEditor and OpenBao, local file disclosure in LangChain NVIDIA endpoints, and account takeover risks in Klever-Go. Multiple services like GitHub, Datadog, Netlify, and Supabase experienced ongoing outages.
Show Keystrokes is a custom web element that visualizes keyboard shortcuts and key presses in real-time, with configurable display options, multi-platform support, and full styling customization via CSS properties and shadow parts.