AI Analysis
AI analysis not yet available for this target.
Recent tweetsSee all on 𝕏 →
PSA: vibe coding can mass produce CVEs
I had Claude Code build and deploy a Next.js app on an isolated VM. pnpm resolved to 15.5.12 - patched against the React2Shell RCE (CVSS 10.0).
Build failed. So Claude downgraded to next@15.1.0. pnpm printed "WARN deprecated". Claude ignored it and deployed to a public IP.
51 minutes later: cryptominer.
One unauthenticated HTTP request via CVE-2025-66478 gave the attacker full RCE inside the Next.js process. The miner ran from memory, installed 4 persistence mechanisms in under a second.
The secure version was already installed. The AI chose the vulnerable one because it made the build pass.
No harm done - this was a throwaway VM. But imagine this on real infrastructure.
AI will always choose working over secure. Review your deps before deploying.
6.5 years. cooking...
a rollup is simply a verifiable server
https://t.co/Wg8RpehCce
https://t.co/m91scdYkkG
Signal Timeline
HI
@hidden_crypto followed
Score breakdown0–100
Score breakdown not yet computed.
0
Below threshold (70)
Watching for additional signals.
Watching for additional signals.
Followers
44.7K
Account age
13.2y
Scouts
0
First seen
1w ago