Compromised npm package silently installs OpenClaw on developer machines

A new security bypass has users installing AI agent OpenClaw — whether they intended to or not. Researchers have discovered that a compromised npm publish token pushed an update for the widely-used Cline command line interface (CLI) containing a malicious postinstall script. That script installs the wildly popular, but increasingly condemned, agentic application OpenClaw on…

Read More

How to choose the best LLM using R and vitals

Is your generative AI application giving the responses you expect? Are there less expensive large language models—or even free ones you can run locally—that might work well enough for some of your tasks? Answering questions like these isn’t always easy. Model capabilities seem to change every month. And, unlike conventional computer code, LLMs don’t always…

Read More

What next for junior developers?

Everyone is worried about junior developers. What are all these fresh-faced computer science graduates going to do now that AI is writing all the code?   It is a legitimate concern.  It wasn’t that long ago that the best advice I could give an early-career person interested in software development was to go to a boot camp. Sure,…

Read More