Pelle Wessman

@voxpelli
649 Followers
835 Following
4.2K Posts
Web developer, +10 years of web dev, creator, non-influencer, open source contributor, #nodejs user, #IndieWeb participant, #TypesInJs advocate. Lives in southernmost Sweden 🇸🇪
GitHubhttps://github.com/voxpelli
Blueskyhttps://bsky.app/profile/voxpelli.com
Bloghttps://voxpelli.com
Profilehttps://kodfabrik.se
I hope all Americans are either happy in how their country is directly and indirectly causing hell on earth in the Middle East or are actively protesting against it. Having friends and colleagues who are seeking refuge from bombs that these other friends and colleagues are enabling. It’s lunacy 🤬

Our first major update of 2026 — Dublin — is out of beta!

This release includes plenty of things you’ve asked us for; selection colors, independent borders, corner smoothing controls, and an all-new eyedropper with Color Variable support. Plus 150+ improvements and fixes.

https://youtu.be/BcECFIQhuZE

New in Sketch: Selection colors, better corners, independent corners, and so much more

YouTube

 Check out the complete list of what's new for Iconfactory Tapestry 1.8 then download it for free.

https://tapestry.iconfactory.com/history

https://apps.apple.com/app/tapestry-by-iconfactory/id6448078074

🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week.

Multiple high-impact maintainers have all confirmed they were targeted in the same coordinated social engineering campaign that compromised Axios.

https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers

Attackers Are Hunting High-Impact Node.js Maintainers in a C...

Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Socket
And this is what that app contained. (Thankfully I never ran it)
If it’s anything like what they attempted with me then a new modus operandi is to create social credibility and even group pressure, then have a planned video call on a faked version of a real streaming service, then show credible errors and urge to download a native app. This is what I got:

RE: https://bsky.app/profile/did:plc:n6f3j47vjucu5ijwdmow7n2w/post/3mijss2fl2k2j

#NPM #axios maintainer has lost control of their account. Malicious versions 1.14.1 and 0.30.4 have been published which include a RAT.

NPM has pulled the effected versions and the payload. Time to clean up and see if you were effected.

StepSecurity has an awesome write up on this issue with #iocs

Link follows this toot.

#CTI #infosec #node #cybersecurity #security #nodejs #js #malware

Ivory v2.5 is now available in the App Store!

What's new:
- Audio Playback (including support for posting audio files)
- Configure 4 Swipe Gestures for Posts
- Support for Viewing Rich Text Posts
- Various bug fixes.

Download the update here:
https://apps.apple.com/us/app/ivory-for-mastodon-by-tapbots/id6444602274

RE: https://mastodon.social/@stroughtonsmith/116255419547147086

This is why I find https://setapp.com/ to be a great thing – on MacOS and iOS alike.

It lowers the threshold to get started with a subscription.

@stroughtonsmith Any thoughts on adding Pastel to Setapp?

Here to say that Eurosky.social seems to have issues. Good to have an account here as well then 🥳