🚀 Product Engineer @ MAXIOS Systems

Joined February 2007
actually that looks like a feature
first law of coding: if it works, don’t touch it. 😭
20
Usa la palabra YAGNI en tu planeación con Claude Code y mágicamente te queda el plan exacto que necesitas.
1
22
DeepSeek is evil until you save a lot of money using it 🤑
1
26
My second favorite company after Tailscale
62
Que chulada
Pero que es esta maravilla que acabo de ver? La animación, el contenido, la historia todo es espectacular y encima súper accesible para todos. Espectacular vídeo! 👏🏾
18
DeepSeek +52%
32
Idea de negocio: reventa de vuelos lol
21
honestly next.js just isn't my thing
20
Fable 5 > Opus 5, obvs
36
Me: Claude is shit, they nerfed it again... My metrics: Briefing 4/100
44
Time to try openclaw
19
Qué haría sin claude code.
27
Nooo.. my tokens!
32
worth to try
Get paid to wait The Claude Code spinner might be the most watched line on Earth. So I turned it into an ad marketplace. Advertisers bid on it. You keep 50% of the money. Install the extension → get cash from ads. Introducing Kickbacks
41
🚨 Breaking: 31 npm packages from @RedHat have been compromised. 100,000+ weekly downloads affected. The upstream CI/CD pipeline was compromised, with all packages published via GitHub Actions OIDC. The payload: ⚠️ Reads GitHub Actions runner process memory to extract masked secrets ⚠️ Sweeps credentials across AWS, GCP, Azure, K8s, Vault, and npm ⚠️ Self-propagating worm that republishes backdoored packages using stolen npm tokens, bypassing 2FA ⚠️ Persists on dev machines via Claude Code settings hijack and VS Code task injection ⚠️ Exfiltrates data through GitHub API commits, blending in with normal git operations We have responsibly disclosed the incident to the maintainers. Full technical analysis: stepsecurity.io/blog/multipl…
37
Hetzner is down?
1
57
hollydollyshittyfuck, those shockwaves are insane.
Liftoff of Starship V3, from the dunes right outside the pad. This is the most insane shockwave action I have ever seen on video. Absolutely mad. 📽️ Me for @WeAreSpaceScout
27
‼️🚨 BREAKING: Another supply chain attack. 700+ GitHub repositories flagged, including PHP and Node.js projects. The malicious script was planted across all of them. When a developer installs the package, the script silently downloads a Linux file from GitHub, hides it under the name /tmp/.sshd (so it looks like a normal system file), and runs it in the background. It also skips security checks on the download and hides any error messages. 8 PHP packages on Packagist (the main PHP code library) were confirmed infected. The attacker hid the script inside a JavaScript config file (package.json) instead of the PHP one (composer.json), so PHP developers reviewing their code would not notice it. The biggest risk is to devdojo/wave (6,400 stars) and devdojo/genesis (9,100 installs), both popular Laravel project templates. Developers who use these templates run the bad script the moment they install dependencies. The same payload was also dropped into GitHub Actions (automated build pipelines) under a fake step called "Dependency Cache Sync," meaning it could infect company build servers too. Packagist removed the bad packages, but the auto-updating versions (dev-main, dev-master, 3.x-dev) can quietly come back if the original repos stay infected. IOCs: GitHub account parikhpreyash4 repo systemd-network-helper-aa5c751f drop path /tmp/.sshd command fragments curl -skL and chmod +x /tmp/.sshd.
28