From 1f3d5c57e76ebca86807c6c94e653307f6a41917 Mon Sep 17 00:00:00 2001 From: Dimi8146 <88474543+Dimi8146@users.noreply.github.com> Date: Tue, 9 Sep 2025 11:16:29 -0500 Subject: [PATCH 1/3] Update 2025-09-11-socratic-seminar-69.md Add NPM Incident --- _posts/2025-09-11-socratic-seminar-69.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/_posts/2025-09-11-socratic-seminar-69.md b/_posts/2025-09-11-socratic-seminar-69.md index c879a65..d477234 100644 --- a/_posts/2025-09-11-socratic-seminar-69.md +++ b/_posts/2025-09-11-socratic-seminar-69.md @@ -88,3 +88,10 @@ Utreexo BIP drafts published by @kcalvinalvinn, co-authored by @tdryja and David - BIP drafts: https://github.com/bitcoin/bips/pull/1923 - Mail list post: https://groups.google.com/g/bitcoindev/c/W1lxBraKG_E - Utreexo is a proposed alternative to the UTXO set; more info at https://bitcoinops.org/en/topics/utreexo/ + +## NPM Malicious Package Incident + +https://x.com/P3b7_/status/1965094840959410230 +https://x.com/P3b7_/status/1965336272550899932 + +$66 stolen in widespread supply chain attack; the developer of a dozen high-impact javascript packages was phished and these packages turned malicious. The NPM security team cleaned up quick and internet-citizen reporting was early and widespread, minimizing impact. From 60ac08c406b81373527e0bff80dae17d02700d84 Mon Sep 17 00:00:00 2001 From: Dimi8146 <88474543+Dimi8146@users.noreply.github.com> Date: Tue, 9 Sep 2025 11:23:15 -0500 Subject: [PATCH 2/3] Update 2025-09-11-socratic-seminar-69.md --- _posts/2025-09-11-socratic-seminar-69.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/_posts/2025-09-11-socratic-seminar-69.md b/_posts/2025-09-11-socratic-seminar-69.md index d477234..09f5f6a 100644 --- a/_posts/2025-09-11-socratic-seminar-69.md +++ b/_posts/2025-09-11-socratic-seminar-69.md @@ -89,9 +89,9 @@ Utreexo BIP drafts published by @kcalvinalvinn, co-authored by @tdryja and David - Mail list post: https://groups.google.com/g/bitcoindev/c/W1lxBraKG_E - Utreexo is a proposed alternative to the UTXO set; more info at https://bitcoinops.org/en/topics/utreexo/ -## NPM Malicious Package Incident +## NPM Malicious Packages Incident https://x.com/P3b7_/status/1965094840959410230 https://x.com/P3b7_/status/1965336272550899932 -$66 stolen in widespread supply chain attack; the developer of a dozen high-impact javascript packages was phished and these packages turned malicious. The NPM security team cleaned up quick and internet-citizen reporting was early and widespread, minimizing impact. +$66 stolen in widespread supply chain attack. The developer of a dozen high-impact javascript packages was phished and these packages turned malicious. The NPM security team cleaned up quick and internet-citizen reporting was early and widespread, minimizing impact. From d0f25ef910eee5db33297f102debb08caaae983e Mon Sep 17 00:00:00 2001 From: Dimi8146 <88474543+Dimi8146@users.noreply.github.com> Date: Tue, 9 Sep 2025 11:24:28 -0500 Subject: [PATCH 3/3] Update 2025-09-11-socratic-seminar-69.md Knobs text update. --- _posts/2025-09-11-socratic-seminar-69.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/_posts/2025-09-11-socratic-seminar-69.md b/_posts/2025-09-11-socratic-seminar-69.md index 09f5f6a..118f10c 100644 --- a/_posts/2025-09-11-socratic-seminar-69.md +++ b/_posts/2025-09-11-socratic-seminar-69.md @@ -35,8 +35,7 @@ https://github.com/bitcoinknots/bitcoin/releases/tag/v29.1.knots20250903 https://github.com/TABConf/bitcoinknobs -Bitcoin Knobs is a fork of Bitcoin Knots that takes flexibility a step further. Where others decide what is "safe" or "reasonable," we believe in maximum choice. If that means your node refuses to start, your wallet vanishes into the void, or your peers pretend you don't exist, at least the decision was yours. -ody sane would touch. Some people call that dangerous. We call it feature-complete. +Bitcoin Knobs is a fork of Bitcoin Knots that takes flexibility a step further. Where others decide what is "safe" or "reasonable," we believe in maximum choice. If that means your node refuses to start, your wallet vanishes into the void, or your peers pretend you don't exist, at least the decision was yours. Because freedom means being able to tune every setting, even the ones nobody sane would touch. Some people call that dangerous. We call it feature-complete. ## Nunchuk releases Miniscript + E2EE group wallets