Damus
jonny (nonvenomous) · 5w
I am just chanting "please don't be a hoax please don't be a hoax please be real please be real" looking at the date on the calendar
jonny (nonvenomous) profile picture
I'm seeing people on orange forum confirming that they did indeed see the sourcemap posted on npm before the version was yanked, so I am inclined to believe "real." Someone can do some kind of structural ast comparison or whatever you call it to validate that the decompiled source map matches the obfuscated release version, but that's not gonna be how I spend my day https://news.ycombinator.com/item?id=47584540
1
jonny (nonvenomous) · 5w
There is a lot of clientside behavior gated behind the environment variable USER_TYPE=ant that seems to be read directly off the node env var accessor. No idea how much of that would be serverside verified but boy is that sloppy. They are often labeled in comments as "anthropic only" or "internal on...