HNHacker News
TopNewBestAskShowJobs

somebudyelse

48 karma · joined March 27, 2026

submissionscomments
somebudyelse··on System-level ad-blocking in Android
Highly recommend https://nextdns.io, great for all kinds of blocking stuff. Plus Firefox or Edge for uBlock support.
somebudyelse··on When did Google get so weird?
https://udm14.org/ for anyone needing an AI-free version
somebudyelse··on 99% of My Website Traffic Is Bots
I visited someone's blog and didn't have to solve a cloudflare challenge! That's amazing work
somebudyelse··on Keyv and friends compromised in active Shai-Hulud supply chain attack
I ended up asking my agent with auto mode:

can you search all installed node modules for any sign of the shai hulud supply chain attack? What happened Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a "preinstall": "node setup.mjs" entry added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed.

setup.mjs is a heavily obfuscated dropper. Its only job is to silently download the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/ and use it to execute the real payload, Math_Symbol.js:

execFileSync(<bun binary>, ['<script_dir>/Math_Symbol.js'], { stdio: 'inherit', cwd: <script_dir> }) The Math_Symbol.js is a heavily obfuscated 728 KB JavaScript file containing credential stealers that harvest secrets from the victim's environment, encrypt the findings, and exfiltrate them to a public GitHub repository whose description reads "Shai-Hulud: Here We Go Again". The payload also contains worm-like propagation functionality to infect packages of other maintainers that have installed one of the compromised packages.

somebudyelse··on Keyv and friends compromised in active Shai-Hulud supply chain attack
when i was searching i got a heartattack when i saw Math_Symbol.js. Thankfully my agent was able to figure it out.
somebudyelse··on Keyv and friends compromised in active Shai-Hulud supply chain attack
the irony of the update being at 1337
somebudyelse··on Tailscale didn't stop the Hugging Face intrusion
Tailwind or Tailscale?

I think the case is Tailscale is saying, "It's technically not our fault, but we still should've stopped it."

somebudyelse··on Show HN: Orbit – AR satellite tracker, watch 15k+ objects
Any hope of open sourcing or android?
somebudyelse··on Raspberry Pi 5 – 16GB RAM
Earliest snapshot from IA is $120. That's almost 3x increase since then. I knew the component shortage was bad but not this bad.

https://web.archive.org/web/20250529094904/https://www.adafr...

somebudyelse··on CBP Directive 3340-049B: Border Search of Electronic Devices
Don't think this is anything new? Have seen various cases from years ago where they searched texts to determine if the person was planning on working or visiting.

Edit: the first directive apparently was from 2009: https://www.jdsupra.com/legalnews/new-policy-for-device-sear...

somebudyelse··on Incident Report: CVE-2024-YIKES
If you really want to make sure that it's the right thing (because piping to sudo bash is risky), make sure the URL starts with "pastebin", or ends in ".tk", or is an IP address.
somebudyelse··on Incident Report: CVE-2024-YIKES
Too soon
somebudyelse··on You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)
Let's see... That's 4 Linux LPEs in the last 10 days?

Copy Fail [1]

Copy Fail 2: Electric Boogaloo [2]

Dirty Frag [3]

And now this...

[1]: https://copy.fail

[2]: https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boo...

[3]: https://github.com/V4bel/dirtyfrag

somebudyelse··on Canvas is down as ShinyHunters threatens to leak schools’ data
It looks like Instructure has been removed from the ShinyHunters website. Both the entry and the list of schools has been removed.
somebudyelse··on Canvas online again as ShinyHunters threatens to leak schools’ data
Somewhat similar vein, the school's blocking software would block YouTube and embeds unless they came from Canvas. They were smart enough to disable the HTML editor for posting discussion comments, but forgot that since it was a rich text editor, you could just copy-paste in an embed by putting the code in data:text/html, then copying the element as formatted html.

I also ran the entire DOMPurify sample XSS and managed to find one way to download custom content onto someone's computer.

somebudyelse··on Canvas is down as ShinyHunters threatens to leak schools’ data
It looks like Instructure has been removed from the ShinyHunters website. Both the entry and the list of schools has been removed.
somebudyelse··on I decompiled the White House's new app
The only permissions on the play store are notifications. On data privacy, it only shows optional email or phone number. Respectfully, I call BS.
somebudyelse··on I decompiled the White House's new app
As someone who has an MDM-managed device, I beg to differ. Although, this one uses newer style android MDM, which involves factory resetting and doing special things during OOBE. Even if it used the older style, nothing's stopping the app for requesting file access, notification access, etc. and not working until you grant the permissions.