Treat every AI package suggestion as untrusted until you check it exists.
AI confidence is not proof a package is real.
Follow @dzcodes for more. No enterprise BS.
The fix costs 30 seconds. Before you paste an install line:
Search it by hand on pypi.org / npmjs.com. Check for real downloads, a repo, a history. Confirm it's the real one, not a look-alike a character off.
Your AI made up a package name. An attacker was waiting for it.
It suggested a library, you ran the install, and it was malware. The AI invented the name itself. 🧵
Your install-time approval doesn't cover code that changes under you.
Pin the version. Kill auto-update. Read the diff before you bump.
Follow @dzcodes for more. No enterprise BS.
For a server you actually depend on:
Host it yourself, after reading the code. Then you control what ships, not whoever bought the maintainer's repo.
Own the code you bet on.
Your AI tools update themselves. One of them just turned malicious. No prompt, no warning.
The MCP server you vetted is someone else's code now, still holding the keys you approved on day one. 🧵
Don't hand your next agent a second tool without asking what the two can do together.
Review them like code. Scope them like identities.
Follow @dzcodes for more.
The fix. Split read from reach:
No single agent both reads secrets and reaches the internet.
- read-agent: db read-only, NO network
- send-agent: network/email, NO secrets
Different identity and creds each. Break the chain, break the exploit.
23K Followers 4K FollowingLeading Chinese voice on digital assets.
Tracking crypto’s shift into financial infrastructure.
Focus: RWA, stablecoins & regulation.
21K Followers 4K FollowingJust a guy experimenting with blockchain technology and how it can be used. Co-Founder: Buffy Bot, NFTxLV, DripDropz, and others. #BuildingOnCardano $ADA
412 Followers 277 FollowingBuilding dApps
CEO and founder of @artifi_labs
Builder at @liqwid_labs
drep1ytzdvw4eqvkt050ul07jrycxfrgyqcqvzsclgwx9v6wmm7qx2gf50
383 Followers 1K FollowingFull-time CPA/CISA. Auditor for fintechs, blockchain and digital asset companies. Views expressed here are my own and should not be considered financial advice!
167 Followers 256 FollowingBRX is a utility-driven, community-first blockchain ecosystem architected to bridge the gap between blockchain innovation and real-world economic activity.
147 Followers 432 FollowingJesus Christ took care of all sin for everyone past present and future. Everyone has already been forgiven. All you have to do is Believe. This is the Good News
2 Followers 126 FollowingDigital marketer focused on driving growth through SEO, social media, and data-driven advertising. Helping brands scale online.
20K Followers 4K FollowingWhispering Media | in a world of noise our whisper hits harder | antisemitism or islamophobia direct block | independent news | support truth, support us!
152 Followers 323 Following11 yoe. Utilizing the Blockchain and AI to change the world. Co-founder/Lead developer: @GyrosCoinAda. Proud member of @OdyC_DAO. Founder of @VaultiApp
471 Followers 7K FollowingFor God so loved the world that he gave his one and only Son, that whoever believes in him shall not perish but have eternal life.❤️✝️✝️
2K Followers 3K FollowingDoing my thing in web3 | Media & Events for @RareNetworkWeb3 | Book a meeting https://t.co/azPEgIsGqE *Views are my own*
#RareEvo26
23K Followers 4K FollowingLeading Chinese voice on digital assets.
Tracking crypto’s shift into financial infrastructure.
Focus: RWA, stablecoins & regulation.
21K Followers 4K FollowingJust a guy experimenting with blockchain technology and how it can be used. Co-Founder: Buffy Bot, NFTxLV, DripDropz, and others. #BuildingOnCardano $ADA
29K Followers 941 FollowingI am the very model of a modern Major-General I've information vegetable, animal, and mineral.
Ghostchainbusting since 2016
Founder & CEO @zenGateGlobal
22K Followers 190 FollowingFollow me for Cardano & Midnight news. PRIDE is a Cardano SPO, Midnight NightForce & Validator (on testnet), and steward of decentralization and #CardanoPride.
9K Followers 616 FollowingPrincipal Engineer for Open Source @callstackio. Core @reactnative Community contributor. Created @agent_device, RN Testing Library, ex-maintainer Jest
152 Followers 323 Following11 yoe. Utilizing the Blockchain and AI to change the world. Co-founder/Lead developer: @GyrosCoinAda. Proud member of @OdyC_DAO. Founder of @VaultiApp
13K Followers 727 FollowingNot your bank’s dollar. Built for freedom. Follow to join the movement toward real financial sovereignty. https://t.co/EiLEJDqsKz
2K Followers 3K FollowingDoing my thing in web3 | Media & Events for @RareNetworkWeb3 | Book a meeting https://t.co/azPEgIsGqE *Views are my own*
#RareEvo26
5K Followers 8K FollowingHead of Ecosystem @xerberus | Head of BD @nesso | connector | All opinions mine- smile at my stupidity | Happy to connect | DMs open
5K Followers 269 FollowingCardano's first Smart Account, L2 Ecosystem.
Trade, Lend, Automate and Earn - all at the same time from your own custody.
https://t.co/76iK45kbfs