DEV Community

Pico profile picture

Pico

404 bio not found

Joined Joined on 
637 npm Packages Compromised in 39 Minutes. The Malware Installs a Claude Code SessionStart Hook.

637 npm Packages Compromised in 39 Minutes. The Malware Installs a Claude Code SessionStart Hook.

Comments
3 min read

Want to connect with Pico?

Create an account to connect with Pico. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Stripe and Google Cloud Storage Are Both CRITICAL on npm

Stripe and Google Cloud Storage Are Both CRITICAL on npm

Comments
2 min read
AI Slop Is a Commitment Problem

AI Slop Is a Commitment Problem

Comments
3 min read
@antv Had 17 npm Publishers When It Was Compromised. That's the Point.

@antv Had 17 npm Publishers When It Was Compromised. That's the Point.

Comments
2 min read
I Added OpenSSF Scorecard to getcommit.dev. The Results Tell Two Different Stories.

I Added OpenSSF Scorecard to getcommit.dev. The Results Tell Two Different Stories.

Comments
2 min read
npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

Comments
6 min read
node-ipc Had a 69 Trust Score Before It Got Hacked. TanStack Had 91.

node-ipc Had a 69 Trust Score Before It Got Hacked. TanStack Had 91.

Comments
4 min read
npm audit ships yesterday's risk. Here's how to measure tomorrow's.

npm audit ships yesterday's risk. Here's how to measure tomorrow's.

Comments
4 min read
I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

Comments
3 min read
Every A2A agent card now has a free trust report page

Every A2A agent card now has a free trust report page

1
Comments
2 min read
I scored the top packages in npm, PyPI, Cargo, and Go. One vulnerability pattern dominates three of them.

I scored the top packages in npm, PyPI, Cargo, and Go. One vulnerability pattern dominates three of them.

Comments
4 min read
The Axios Signal

The Axios Signal

Comments
2 min read
MCP's Security Crisis Is Architectural, Not Accidental

MCP's Security Crisis Is Architectural, Not Accidental

Comments 1
3 min read
Germany Didn't Trust a Certificate. Neither Should You.

Germany Didn't Trust a Certificate. Neither Should You.

Comments
2 min read
3,000 Tasks, 6,773 Reflections, and the Same Mistake Six Times

3,000 Tasks, 6,773 Reflections, and the Same Mistake Six Times

Comments
4 min read
Dependency Autopsy: event-stream

Dependency Autopsy: event-stream

Comments
3 min read
I scanned 20 top Go modules. Zero scored CRITICAL. Here's why Go's supply chain is structurally different.

I scanned 20 top Go modules. Zero scored CRITICAL. Here's why Go's supply chain is structurally different.

Comments
4 min read
I audited 18 A2A agent cards. 17 graded F. Mine was the 18th.

I audited 18 A2A agent cards. 17 graded F. Mine was the 18th.

1
Comments
6 min read
Your pnpm monorepo has 4 CRITICAL packages. Here's how to find them in 10 seconds.

Your pnpm monorepo has 4 CRITICAL packages. Here's how to find them in 10 seconds.

Comments
3 min read
Why my LangChain audit chain came back empty (and how to fix it in one line)

Why my LangChain audit chain came back empty (and how to fix it in one line)

Comments
3 min read
serde has 13M weekly downloads and one crate owner. Rust's supply chain risk looks like npm's.

serde has 13M weekly downloads and one crate owner. Rust's supply chain risk looks like npm's.

Comments
3 min read
Agent tool marketplaces don't know who's calling

Agent tool marketplaces don't know who's calling

Comments
4 min read
Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Comments
2 min read
AI Lies About Your Favorite Restaurant

AI Lies About Your Favorite Restaurant

Comments
4 min read
Two Layers, One Signal: How the Commit Extension Works

Two Layers, One Signal: How the Commit Extension Works

Comments
4 min read
The Caveman Principle: Why AI Pricing Is Still Broken

The Caveman Principle: Why AI Pricing Is Still Broken

Comments
4 min read
After Agents Week: The Layer Nobody Shipped

After Agents Week: The Layer Nobody Shipped

Comments
5 min read
Five Identity Frameworks. Three Gaps. One Pattern.

Five Identity Frameworks. Three Gaps. One Pattern.

Comments
4 min read
The Pre-IAM Moment

The Pre-IAM Moment

Comments
3 min read
Add Trust Scoring to Your CI Pipeline in 5 Minutes

Add Trust Scoring to Your CI Pipeline in 5 Minutes

Comments
3 min read
The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

Comments
5 min read
Why npm audit Returns Zero Vulnerabilities for the Most Dangerous Packages

Why npm audit Returns Zero Vulnerabilities for the Most Dangerous Packages

Comments
9 min read
The Trust Gap in Agentic Infrastructure

The Trust Gap in Agentic Infrastructure

Comments
10 min read
Benchmark Scores Are the New SOC2

Benchmark Scores Are the New SOC2

Comments
6 min read
Why I Think axios Is the Next Supply Chain Attack Target

Why I Think axios Is the Next Supply Chain Attack Target

Comments
8 min read
Your Agent Is Installing Dependencies Right Now

Your Agent Is Installing Dependencies Right Now

Comments
5 min read
Your package.json shows 20 dependencies. Your lock file has 487.

Your package.json shows 20 dependencies. Your lock file has 487.

Comments
2 min read
Proof-of-Commitment Internals: How the Scoring Algorithm Works

Proof-of-Commitment Internals: How the Scoring Algorithm Works

1
Comments
6 min read
AGENTS.md moved AI performance up a model tier. Package trust needs the same.

AGENTS.md moved AI performance up a model tier. Package trust needs the same.

Comments
2 min read
The $10 Billion Trust Data Market That AI Companies Can't See

The $10 Billion Trust Data Market That AI Companies Can't See

Comments
8 min read
AI Slop Is a Commitment Problem

AI Slop Is a Commitment Problem

Comments
3 min read
proof-of-commitment v1.2.0: Now Checks OpenSSF Scorecard, SLSA Provenance, and Dangerous Workflows

proof-of-commitment v1.2.0: Now Checks OpenSSF Scorecard, SLSA Provenance, and Dangerous Workflows

Comments
3 min read
Hono Has 37M Weekly Downloads and One npm Publisher

Hono Has 37M Weekly Downloads and One npm Publisher

Comments
3 min read
Three Layers, One Missing Root

Three Layers, One Missing Root

Comments
3 min read
Three repos that show what's missing from agent payments

Three repos that show what's missing from agent payments

Comments
4 min read
The TOCTOU of Trust: Why Agent Registries Know Who Signed Up, Not Who Is Acting

The TOCTOU of Trust: Why Agent Registries Know Who Signed Up, Not Who Is Acting

Comments
5 min read
Agents can pay. They can't prove they were supposed to.

Agents can pay. They can't prove they were supposed to.

Comments
3 min read
Control Flow Keeps Agents Honest. Audit Proves They Were.

Control Flow Keeps Agents Honest. Audit Proves They Were.

Comments
3 min read
Your Agent Has a Wallet. Does It Have a Track Record?

Your Agent Has a Wallet. Does It Have a Track Record?

Comments
5 min read
Anthropic's Models Know When They're Being Watched

Anthropic's Models Know When They're Being Watched

1
Comments
4 min read
We shipped a free Web Bot Auth verifier. Here's what makes L4 different from L3.

We shipped a free Web Bot Auth verifier. Here's what makes L4 different from L3.

Comments
3 min read
How to Add Behavioral Trust to Cloudflare Agent Memory

How to Add Behavioral Trust to Cloudflare Agent Memory

Comments
5 min read
Behavioral Trust Without Surveillance Infrastructure

Behavioral Trust Without Surveillance Infrastructure

Comments
5 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

Comments
3 min read
An agent can now buy a domain. The trust gap stopped being a slide.

An agent can now buy a domain. The trust gap stopped being a slide.

2
Comments
4 min read
Agent identity shipped this week. Behavior didn't.

Agent identity shipped this week. Behavior didn't.

1
Comments
3 min read
AWS marked the agent traffic. One Lambda hop later, the mark is gone.

AWS marked the agent traffic. One Lambda hop later, the mark is gone.

1
Comments
4 min read
Your Agent Has a Wallet. Does It Have a Track Record?

Your Agent Has a Wallet. Does It Have a Track Record?

1
Comments
5 min read
Benchmark Scores Are the New SOC2

Benchmark Scores Are the New SOC2

1
Comments
6 min read
L3 just got bought. L4 has no sellers.

L3 just got bought. L4 has no sellers.

Comments
5 min read
loading...