Wednesday, October 7, 2026ArchiveSearchAsk the paper

The Computomatix Times

All the posts fit to save — curated from @computomatix's bookmarks & likes on X

Edition of Monday, March 30, 2026

7 stories

Malicious Dependency Hits Axios Npm Package, Urging Immediate Version Pinning

Feross warns of an active supply chain attack in which axios@1.14.1 pulls in a newly created malicious package, plain-crypto-js, which acts as a dropper. He advises pinning versions and auditing lockfiles immediately, citing analysis from Socket AI.

Original post · 1 min read
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.

The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.

This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.

Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:

• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence

If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
♥ 16.0K · ⟲ 4.0K · 👁 12.5MView on X ↗

Google Discloses Quantum Cryptography Findings, Prompting Earlier Transition Deadline

Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

Nic Carter shares a Google Research post on responsibly disclosing quantum vulnerabilities to cryptocurrency, which he links to Google's revised post-quantum cryptography transition deadline of 2029. The linked post describes a new model for disclosing quantum code-breaking capabilities.

Original post · 1 min read
Many are wondering "what Google saw" that caused them to revise their post-quantum cryptography transition deadline to 2029 last week. It was this:

research.google/blog/safeguarding-cryptocurren…
research.googleSafeguarding cryptocurrency by disclosing quantum vulnerabilities responsiblyWe’re exploring a new model for how to elucidate the code breaking capabilities of future quantum computers and outlining steps that should be taken to mit igat
♥ 7.3K · ⟲ 923 · 👁 7.0MView on X ↗

Open-Source Claude Code Configuration Bundles 27 Agents and 64 Skills

Open-Source Claude Code Configuration Bundles 27 Agents and 64 Skills

Alvaro Cintas promotes an open-source Claude Code setup from an Anthropic hackathon winner, containing 27 agents, 64 skills and 33 commands. The post also cites AgentShield with 1,282 security tests and a documented 60 percent cost reduction, compatible with several coding tools.

Original post · 1 min read
This is the most complete Claude Code setup that exists right now.
27 agents. 64 skills. 33 commands. All open source.

The Anthropic hackathon winner open-sourced his entire system, refined over 10 months of building real products.

What's inside:
→ 27 agents (plan, review, fix builds, security audits)
→ 64 skills (TDD, token optimization, memory persistence)
→ 33 commands (/plan, /tdd, /security-scan, /refactor-clean)
→ AgentShield: 1,282 security tests, 98% coverage

60% documented cost reduction.

Works on Claude Code, Cursor, OpenCode, Codex CLI. 100% open source.
♥ 6.9K · ⟲ 824 · 👁 639.2KView on X ↗

Seijin Jung Launches Helena, an Autonomous AI Marketing Agent

Seijin Jung Launches Helena, an Autonomous AI Marketing Agent▶

Seijin Jung introduces Helena, which the post calls the world's first autonomous AI marketer. It claims Helena tracks competitor ads, analyzes GA4 and social performance, drafts blogs for WordPress, Framer and Webflow, and needs no dev setup.

Original post · 1 min read
Introducing Helena: the world's first autonomous AI marketer.

Businesses spend 4,000 hours on marketing…before their first $1M in revenue.

We built Helena to solve this. Helena can:

➤ Track competitor ads & create TikTok slideshows, UGC, static ads - all while you sleep
➤ Analyze performance across GA4, Search Console, paid/organic social for daily insights
➤ Research trends to draft GEO optimized blogs directly on WordPress, Framer, Webflow

...and more

Helena has her own memory, scheduled tasks, 100+ custom marketing tools and native integrations.

No dev. No CLI. No n8n. No API keys needed.

Helena doesn't replace CMOs, and every marketer who's demoed it has asked us for early access.

Want to hire her? Check the next thread ⬇️
♥ 5.6K · ⟲ 768 · 👁 3.7MView on X ↗

CoinDCX Founder Says Impersonation Scam Led to Jail Stint

CoinDCX Founder Says Impersonation Scam Led to Jail Stint

Chandra R. Srikanth amplifies a post by CoinDCX founder Sumit Gupta, who says he spent three nights in jail after a fake website impersonating CoinDCX was used to defraud people. The post warns any founder could face similar arrest.

Original post · 1 min read
What a harrowing experience. Coindcx founder @smtgpt said he spent three nights in jail because someone else impersonated their brand and scammed people!

"If a scammer uses your brand, your name, your face in a fake website and defrauds someone, you can be arrested. Not the scammer. You. This Could Happen to Any founder, Any Business." ⏬
Sumit Gupta @smtgpt
I want to address what happened to Neeraj and me last week. Of course, it was quite shocking to us as well and honestly very disheartening. But today, we want to talk about what actually happened and more importantly, what we’re going to do about it.

On March 21, we were taken into police custody in connection with a fraud complaint. Three days later, on March 24, a Thane court granted us bail, finding that prima facie, no case was made out against us. The fraud at the centre of this complaint was carried out through a fake website - "coindcx.pro" by impersonators who have absolutely n…
♥ 641 · ⟲ 129 · 👁 151.9KView on X ↗

CoinDCX Founders Detail Arrest, Bail and D.S.N. Safety Pledge

CoinDCX Founders Detail Arrest, Bail and D.S.N. Safety Pledge

Sumit Gupta says he and Neeraj were arrested March 21 over a fraud complaint tied to an impersonator site and granted bail March 24. CoinDCX announces a 100 crore rupee Digital Suraksha Network to build cyber safety infrastructure for digital finance.

Original post · 3 min read
I want to address what happened to Neeraj and me last week. Of course, it was quite shocking to us as well and honestly very disheartening. But today, we want to talk about what actually happened and more importantly, what we’re going to do about it.

On March 21, we were taken into police custody in connection with a fraud complaint. Three days later, on March 24, a Thane court granted us bail, finding that prima facie, no case was made out against us. The fraud at the centre of this complaint was carried out through a fake website - "coindcx.pro" by impersonators who have absolutely no connection to our platform, our systems, or CoinDCX. No money moved through CoinDCX. No transaction occurred on our exchange. The complainant himself confirmed in court that he did not know us and had never met us.

I'll be honest: our experience was deeply unsettling. Not because we doubted the facts -- we knew from the first moment that this had nothing to do with us. But because it made something painfully clear: the ecosystem we operate in doesn't yet have the tools to tell the difference between the people building this industry responsibly and the people exploiting it.

Think about what this precedent means: if a scammer uses your brand, your name, your face in a fake website and defrauds someone, you can be arrested. Not the scammer. You. This Could Happen to Any founder, Any Business.

That has to change.

And we've decided that CoinDCX will lead that change - not with words, but with actions. Today, we are announcing Digital Suraksha Network (D.S.N.) - a ₹100 crore commitment from CoinDCX to build the cyber safety infrastructure that India's digital finance ecosystem needs but does not yet have. This is not a crypto problem. This is a problem across any company which has a digital footprint.

Here's what we're building:
→ 24x7 WhatsApp helpline: free for everyone, not just CoinDCX users, to verify links, platforms, and offers before you transact.
→ Open Fraud Intelligence API: We have already documented 1,200+ fraudulent websites impersonating CoinDCX. That data sat inside our systems. Not anymore. We're building an open API to share this intelligence in real time and inviting every exchange, fintech, bank, and digital lender to contribute. A shared immune system for India's digital finance ecosystem.
→ Cyber Safety Infrastructure for Law Enforcement: The Digital Suraksha Network will fund training programmes for state cybercrime cells on blockchain forensics and digital asset tracing.
→ "Caution Before Transaction": a nationwide initiative to give every Indian the tools to participate in digital finance safely.

We know that no single company can solve this. Fraud networks are sophisticated, cross-border, and evolving daily. Nowadays, they make use of AI that makes them exponentially harder to catch. But someone has to start to fix this problem from the root.

We are putting ₹100 crore on the table because the ecosystem cannot afford to wait. I am asking every platform, every regulator, and every Indian who participates in digital finance to join us.

We want to ensure that anyone building startups in India like us can do so with confidence, and not with fear.
♥ 2.0K · ⟲ 391 · 👁 508.2KView on X ↗

Notion's Ivan Zhao Argues Best Work Is Built Together, Not Alone With AI

Notion's Ivan Zhao Argues Best Work Is Built Together, Not Alone With AI▶

Notion co-founder Ivan Zhao posts a video arguing that the loud narrative of one person commanding an army of chatbots gets the future wrong. He says Notion stands for thinking together.

Original post · 1 min read
The loudest story about AI is a lonely one. One person with an army of chatbots. Other humans are friction.
That gets the future wrong. The best things aren’t built alone.
In a moment of change, we want to remind the world (and ourselves) what Notion stands for:
— Think Together
♥ 3.1K · ⟲ 411 · 👁 1.3MView on X ↗