A detailed takedown argues npm's 2FA cooldowns and account freezes are theater against AI-generated malware, citing recent malicious packages as proof the supply chain is still wide open.
programmingSunday, June 28, 2026
Npm's security theater and the AI code crisis
Today's programming coverage circles two uncomfortable truths: npm's security measures aren't keeping up with AI-generated malware, and the flood of low-quality AI code is creating a new class divide among engineers. The common thread is that the tools we rely on, package registries, code review, even our own skills, are struggling to adapt to an era where code is cheap but trust is expensive.
Security theater
The most pointed critique today targets npm's reactive security measures against a wave of AI-generated malware.
Qodo's cross-repo review tool is a practical response to the AI PR flood, but it's a band-aid on a deeper problem, teams drowning in code they didn't write.
AI code crisis
Beyond supply chain attacks, the quality and sustainability of AI-generated code is under scrutiny from multiple angles.
A stark look at the 'class divide' in software engineering: experienced devs are stuck fixing mountains of bad AI code from 'vibe coders,' fueling an existential crisis.
Codeplain's 'spec-driven development' flips the script: instead of reviewing AI code, regenerate it from specs. Bold idea, but it assumes specs are easier to maintain than code.
The A11y LLM Eval project finds frontier models still default to inaccessible UI code, but explicit instructions and a new 'skills' mechanic show promise, if teams bother to use them.
Also today9
GitHub - cfenollosa/bashblog: A single Bash script to create blogs. Download, run, write, done!github.com
datalab-to/surya-ocr-2 · Hugging Facehuggingface.co
Decomp Academy — Learn GameCube Decompilation (MWCC GC/2.0)decomp-academy.dev
How to Use an E-ink Display with Raspberry Piraspberrytips.comGetting Started with the Radxa X5 SBC on Linuxwww.linux.org
amd-strix-halo-vllm-toolboxes/rdma_cluster/setup_guide.md at main · kyuz0/amd-strix-halo-vllm-toolboxesgithub.com
Your Grid Lanes will likely fail WCAG 2.4.3 - Manuel Matuzovicmatuzo.at
Manuel Matuzovic analyzes why CSS Grid Lanes (Masonry Layouts) are likely to fail WCAG 2.4.3 success criterion for focus order. The article explains how the visual reordering of items in a masonry/grid-lanes layout creates a mismatch between visual presentation and DOM/source ord
AI-Driven Vibe Coding Emerging as Tech Trend in Nepalwww.rswebsols.com
Nepal's software sector is embracing "vibe coding," an AI-driven methodology that allows developers to create applications from simple natural language directives. Nepal Telecom has launched a dedicated software division that has already released several digital platforms, includ
I Built 3 MCP Servers for AI Agents — Here's How They Workdev.to
The article introduces the Model Context Protocol (MCP) as an open standard that unifies how AI agents connect to external tools and data sources, comparing it to USB-C for AI. The author describes building three production-ready MCP servers (for web search, code review, and docu
More roundups that day
energy roundupPakistan's solar surge, Germany's coal wobble
Cerrado crisis and local water fights
