Dagens Vibes — 5. august 2026

Dagens feed handler mindre om den næste model og mere om laget omkring den: sikre dependencies, observerbare agenter, skarpe standarder og sessions, man faktisk kan tage med sig. Modellen er ikke hele produktet længere. Resten af maskinrummet vil også have penge og opmærksomhed.

Fra X-feedet

En aktiv npm-orm ramte keyv, cacheable og breder sig til andre pakker. Den stjæler credentials, spreder sig med maintainerens egne tokens og planter autostart-hooks i .claude og .vscode. Den virkelig muntre detalje: trojaniseret kode kan stadig have gyldig provenance.

npm
Keyv and Cacheable compromised in active supply-chain attackSocket · 4. august 2026 · løbende IoC- og pakkelistehttps://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain
Feross
Feross@feross

🚨 Active supply chain attack on npm: keyv and cacheable are compromised right now, and the payload is a worm. The maintainer account behind both package families was compromised. On August 4, ten packages were republished with a malicious preinstall hook that steals your credentials, then uses those credentials to publish itself into more packages. Malicious versions are live on npm as I write this. These are foundational packages. keyv, cacheable, flat-cache, and file-entry-cache sit deep in dependency trees as transitive deps of common tooling like ESLint. Tens of millions of weekly downloads. Most affected users never installed them directly. What the payload does: • preinstall hook (setup.mjs) downloads a standalone Bun runtime and runs the second stage under it, sidestepping the host Node version and any Node-level monitoring • Harvests cloud and CI credentials: AWS/GCP/Azure keys, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC, and npm tokens • Repackages other npm packages with the same hook and republishes them through npm OIDC trusted publishing. This is what makes it a worm. • Exfiltrates over DNS and by committing stolen secrets to attacker-created GitHub repos • Plants autostart hooks in .claude and .vscode that execute when a developer or an AI coding agent opens the cloned repo. No npm install required. The detail worth sitting with: keyv@6.0.0 shipped with a passing npm provenance attestation. The build pipeline faithfully attested a source that was already trojanized. Signature verification alone did not stop this. Socket’s AI scanner flagged the malicious setup.mjs hook. If you install anything in the keyv, @keyv, or cacheable scopes: • Pin to the last known-clean version and rebuild lockfiles by integrity hash. No caret or tilde ranges, no npm update. • Better: block the entire keyv, @keyv, and cacheable scope at your registry proxy until the account is confirmed clean. • Rotate and revoke every credential reachable from any host that ran install scripts. npm and GitHub tokens should be revoked, not just rotated. Developing story. Socket is updating the affected-package list as new versions appear. Full research report with IoCs: https://t.co/dyjGuLQ5Op If you are dealing with this right now and want help, email sales@socket.dev and we will spin up emergency white-glove assistance.

♥ 137↻ 28💬 17🔖 47
https://x.com/feross/status/2084648858605465801

Cloudflare gør agent-observability til et regulært platformlag: sessions-replay, traces, tool calls, tokens og OTel-eksport i samme billede. En agent kan returnere HTTP 200 og stadig have kørt direkte i grøften; nu får grøften et dashboard.

OTel
Introducing Cloudflare AgentsCloudflare · 4. august 2026 · tracing, replay og agent-drifthttps://blog.cloudflare.com/agents-on-cloudflare/
rita kozlov 🐀
rita kozlov 🐀@ritakozlov

@Cloudflare incredible work from @nevikashah @mattsimpsn @FredKSchott and team read more → https://t.co/D2DvoztBVp

♥ 3↻ 0💬 0🔖 2
https://x.com/ritakozlov/status/2084746594864242766

Samme dag viste Cloudflare den mere interessante organisationsdel: interne RFC'er bliver struktureret som MUST/SHOULD, hentet progressivt af agenter og brugt til at kontrollere kode, designs og incident-rapporter. Det er AGENTS.md efter at have fået governance og slips på.

RFC
How Cloudflare enforces engineering standards using AICloudflare · 4. august 2026 · 230.000 fund og 16.000 blokerede mergeshttps://blog.cloudflare.com/engineering-standards-enforcement
Dillon Mulroy
Dillon Mulroy@dillon_mulroy

RT @dok2001: We have been converting "how we build" @Cloudflare into RFCs with MUST and SHOULD statements that make it easy for agents to r…

Retweetet opslag

Dane Knecht 🦭
Dane Knecht 🦭@dok2001

We have been converting "how we build" @Cloudflare into RFCs with MUST and SHOULD statements that make it easy for agents to read. We are expanding agent enforcement beyond core review to design specs and incident reports. https://t.co/bFGQfKnOja

♥ 71↻ 8💬 1🔖 31
https://x.com/dok2001/status/2084665733837893790
♥ 0↻ 8💬 0🔖 0
https://x.com/dillon_mulroy/status/2084666518445445429

Pi argumenterer for, at den tynde harness er en konkurrencefordel. Databricks målte samme model til over dobbelt forskel i pris mellem harnesses, mens Shopify byggede autoresearch som extension i stedet for at vente på mere fabriksmonteret magi. Lidt hjemmebanereklame, men med faktiske case-studier bag.

π
Pi, Minimal and PerformantEarendil · Databricks, Shopify og context disciplinehttps://earendil.com/posts/pi-autoresearch-and-databricks/
Pi
Pi@pidotdev

Over the past few months Pi has consistently shown up in benchmarks as the best harness for both cost and performance. Earendil engineer @cristinaponcela examines case studies from @databricks and @Shopify highlighting why Pi’s minimalism is the advantage. Blog post below https://t.co/JfeKZ2n8Kn

Medie fra @pidotdev
♥ 1069↻ 76💬 25🔖 492
https://x.com/pidotdev/status/2084602752143954030

Den vigtigere Pi-tekst handler om session-portabilitet: lokale logs bør være kanoniske, compaction læsbar og subagent-handoffs auditerbare. Ellers ejer du ikke sessionen; du har bare fået lov at holde en pose krypterede blobs.

The Session You Cannot Take With YouEarendil · inspection, export, replay, audit og deletionhttps://earendil.com/posts/session-portability/
Dillon Mulroy
Dillon Mulroy@dillon_mulroy

https://t.co/FVALfnALm8

Citeret opslag

Tibo
Tibo@thsottiaux

Given some of the results I'm seeing recently, it's pretty clear Codex is a good harness. But it will seem primitive in 2-3 months and we're about to go through another major evolution in how we use AI at the frontier. The next generation of models need more than your laptop.

♥ 14718↻ 577💬 1700🔖 1683
https://x.com/thsottiaux/status/2084483765158719542
♥ 460↻ 27💬 4🔖 346
https://x.com/dillon_mulroy/status/2084494163677008329

Dex Horthys praktiske context-regel: Når modellen siger “you’re absolutely right” efter endnu en fejl, er trajectory'en ofte forgiftet. Kompaktér det nyttige, start en ren session og stop med at skændes med en sandsynlighedsfordeling.

The Pragmatic Engineer
The Pragmatic Engineer@Pragmatic_Eng

You should start a brand new session as soon as the LLM tells you “you’re absolutely right” or “you were right to push back on that.” @DexHorthy, founder of HumanLayer and coiner of "context engineering": “Once the model starts doing dumb things, there’s four things in your context window that matter: the size, the quality of the information, whether there’s missing information, and then there’s the trajectory (the actual history of what the agent has done). If I say: “make this change”, and the model makes the change and runs the test and fixes it, I have high confidence the next change follows that path. But the example we talked about in “no vibes allowed”: the model makes a mistake, you yell at it, it makes another mistake, you yell at it. And then it’s like, what’s the next message in this conversation? If I read the history, I should probably make another mistake so the human can yell at me. So that’s a great example of time to start over."

Medie fra @Pragmatic_Eng
♥ 24↻ 2💬 1🔖 11
https://x.com/Pragmatic_Eng/status/2084633425076490713

Dagens lille kvittering fra virkeligheden: DeepSeek V4 Flash rettede en reel regressionsbug i Node.js' undici for 3,4 cent. Ét PR er ikke et benchmark, men inspicerbar levering slår “viben føles frontier” hver dag.

Matteo Collina
Matteo Collina@matteocollina

I spent $0.034 with @deepseek_ai flash v4 0731 to fix a bug in @nodejs undici. This is part of my experiment to validate the unsubsidized cost of tokens. This is pretty solid. https://t.co/uGYIfjOroF https://t.co/CnMKuVBg1P

Medie fra @matteocollina
♥ 275↻ 6💬 16🔖 32
https://x.com/matteocollina/status/2084661805368988027

Nyhedsbonus

Anthropic har ifølge Bloomberg indgået en seksårig compute-aftale på 10 milliarder dollars med Volta. 133 MW i Norge, Vera Rubin-systemer og en kryptominer som datacenterpartner: AI-labs er energiselskaber med en chatbot i receptionen.

10B
Anthropic signs $10B deal with AI cloud startup VoltaTechCrunch · 4. august 2026 kl. 21:48 CESThttps://techcrunch.com/2026/08/04/anthropic-signs-10-billion-deal-with-ai-cloud-startup-volta/

Reddit er blevet den mest citerede kilde i ChatGPT, Gemini og Perplexity — og derfor næste slagmark for AI-SEO-spam. Brands planter menneskelignende anbefalinger, mens frivillige moderatorer nu forsvarer hele webbets troværdighed. Internettets sidste autentiske pub har fået content marketing-bureau i hjørnet.

r/
Can Reddit fend off a new wave of AI SEO spam?The Verge · 4. august 2026 kl. 12:00 CESThttps://www.theverge.com/ai-artificial-intelligence/973098/reddit-ai-search-seo-marketing-brands-spam