Digest #220: Red Hat's npm supply chain attack, malware in AI instruction files, AWS Lambda MicroVMs and a 2x faster test suite
This week in DevOps: the Red Hat npm credential-stealing attack, malware in AI agent files, AWS Lambda MicroVMs, Postgres 19 beta, and how to get good at Kubernetes.
This week’s supply chain news is rough: 32 malicious @redhat-cloud-services npm packages stealing credentials via a preinstall hook, and Mitiga finding spyware and 1,230+ leaked API keys hidden inside AI agent instruction files. On the building side, AWS shipped Lambda MicroVMs for running untrusted and AI-generated code in isolation, Postgres 19 hit beta, and one engineer doubled their test suite by dropping per-test SQL migrations.
Feature deployed. Did it actually work?
A change can pass CI and review and still break checkout the moment it deploys. Cleric follows every agent-written change into production, checks that it did what you meant, and gives you a verdict: it worked, fix this, or roll back - See it work on a real change.
Newsworthy stories
Malware in AI instruction files, plus 1,230+ leaking API keys
Inside the Red Hat npm “Miasma” credential-stealing campaign
Tutorials of the week
Videos of the week
Projects of the week
no-mistakes is a Go local Git proxy that runs an AI review, test, and lint pipeline in an isolated worktree before pushing, then opens a clean PR.
Hunk is a terminal diff viewer built for reviewing agent-authored changesets, with inline AI annotations.
BoxBox is a self-hosted file manager for homelabs that supports chunked and resumable uploads.
dbtrail is a point-in-time recovery tool for MySQL that runs time-travel queries and can undo cascade deletes without locks or restores.
oh-my-reddit is a terminal Reddit client on Bubble Tea, with live-streaming comments and automatic browser session reuse.
Orca is an agent orchestrator that runs Claude Code, Codex, and 40+ other CLI agents in parallel within git worktrees from a single desktop app.
Meme of the week
If you have feedback to share or are interested in sponsoring this newsletter, feel free to reach out via LinkedIn or simply reply to this email.






