Intelligence Brief
A malicious `proc-macro1` package, typosquatting t, Modular open-sourced Mojo's compiler, tooling, bui, Two days after Stripe's $7.5 billion acquisition o
60B
cursor acquisition
Today's Insights
A malicious `proc-macro1` package, typosquatting the real maintainer identity `dtolnay`, was pulled into the `arrayref` crate (245 million lifetime downloads, underlying winit, egui, iced, blake3, and Solana/Ethereum tooling) via a compromised maintainer account on August 20, 2026. The payload lived in a build script that downloaded and executed a binary from a Hostwinds VPS at compile time -- running `cargo build` triggered it, no code needed to be called. The Rust Security Response Team yanked all affected packages within 86 to 107 minutes. Separately, Wiz's analysis found the attack's C2 endpoint pattern, one C2 IP's SSL issuer, and its hosting-provider IP range all overlap with infrastructure Microsoft and Mandiant previously attributed to North Korean state actors in unrelated npm supply-chain campaigns (Mastra, axios) -- an overlap, not a confirmed attribution.
Modular open-sourced Mojo's compiler, tooling, build system, and 450,000+ lines of Mojo-authored kernel code under Apache 2.0 with LLVM exceptions on August 18, 2026, one week after Mojo reached its 1.0 release. The repo, modular/modular, topped GitHub Trending at 28,117+ stars. Modular's own announcement states the company does not yet accept outside contributions to the compiler or tooling, targeting 'by the end of this year' -- a license-open, governance-closed split rather than a fully open project on day one.
Two days after Stripe's $7.5 billion acquisition of OpenRouter priced the AI model-routing layer at a frontier multiple, Ramp launched Router.com -- an API for routing, testing, and switching between models from OpenAI, Anthropic, SpaceXAI (the renamed xAI, now under the same SpaceX ownership as its $60B Cursor acquisition), DeepSeek, Moonshot, Minimax, Nvidia, and Z.ai. Ramp commercializes three years of its own internal routing infrastructure, offers it free through the end of 2026, and frames the move explicitly as a direct challenge to OpenRouter. The same Ramp business-spend dataset also shows OpenAI closing on Anthropic in business-user share (roughly 40% to 44%) in Q3-to-date, after Anthropic took the lead in May.
At Black Hat USA 2026, Brave security engineer Artem Chaikin demoed live prompt-injection attacks that succeeded against every AI browser he tested -- Opera's AI browser, Perplexity Comet, and ChatGPT Atlas -- using three distinct hiding techniques: instructions hidden behind HTML, near-invisible text overlaid on an image, and a Reddit comment hidden behind spoiler tags. This concretizes an earlier University of Washington academic finding (4 of 7 agentic browsers vulnerable to same-origin-policy bypass via prompt injection) into a named, technique-specific vendor demonstration -- two independent methods now agree that no shipping AI browser has adequate isolation against prompt injection.
A direct GitHub API read of mattpocock/skills -- today's #2 Trending repo, a Claude Code skills-marketplace project this research session itself runs on via an auto-updated plugin -- shows 227,121 stars against yesterday's API-verified 224,162, a measured 24-hour delta of +2,959. The GitHub Trending board claims only +2,192 stars for the same window, a 1.35x understatement. This extends this vault's ongoing GitHub Trending velocity-integrity checks (a second repo, MoneyPrinterTurbo, measured 0.91x -- a 9% understatement -- in the opposite direction one day earlier), with two data points now showing no consistent bias direction.
Today's top-voted Hacker News story (1,250 points) names a direct double standard: Aaron Swartz faced 13 federal charges and up to 35 years in prison for scraping JSTOR's academic archive in 2010-2011, while Meta, OpenAI, Google DeepMind, and Anthropic have trained large language models on comparably or more aggressively scraped and, in some disclosed cases, pirated content with no criminal exposure -- 'celebrated as pioneers and showered with venture capital' instead, per the framing. A companion story on today's board: AliExpress runs silent WebAudio-based browser fingerprinting that, as a side effect, keeps a browser tab's audio path active long enough to block multipoint Bluetooth headphones from switching back to a paired phone -- invisible to the user, survives Do Not Track, discovered through a hardware symptom rather than a privacy audit.
Trending Repos
- +2,761/d
- mattpocock/skills
Shell
+2,192/d - +1,545/d
- volcengine/OpenViking
Python
+950/d - santifer/career-ops
JavaScript
+816/d