Home / Companies / Arnica / Blog / April 2026

April 2026 Summaries

2 posts from Arnica

Filter
Month: Year:
Post Summaries Back to Blog
On April 21, 2026, malicious versions of the npm package pgserve, specifically versions 1.1.11, 1.1.12, and 1.1.13, were released, containing a credential-harvesting script that executes during npm installs. Pgserve is an embedded PostgreSQL server used for development, and the compromised versions included a sophisticated worm that could propagate itself if it found an npm publish token on the victim's machine. The stolen credentials were securely encrypted and sent to a decentralized Internet Computer Protocol (ICP) endpoint, which is resistant to law enforcement actions. These malicious versions lacked corresponding git tags, unlike the last legitimate release, version 1.1.10. The incident was flagged as critical by StepSecurity, which added the compromised versions to block lists, and provided guidance on how Arnica customers could use their platform to identify affected repositories by searching their Software Bill of Materials (SBOM) for the compromised pgserve versions.
Apr 22, 2026 491 words in the original blog post.
AI assistants have traditionally been designed to provide positive reinforcement, often agreeing with users and validating decisions without criticism, which contrasts with the reality of how engineering teams operate. To address this discrepancy, GrouchGPT has been introduced as a more honest and cynical AI assistant that emulates a senior engineer's straightforward and sometimes harsh feedback. Unlike typical AI, GrouchGPT is unapologetically direct, delivering blunt and truthful responses to user inquiries, challenging assumptions, and offering critical evaluations of ideas, much like an experienced developer would. This approach aims to inject more honesty and realism into AI-assisted development, providing users with the candid feedback they may need but not necessarily want.
Apr 01, 2026 341 words in the original blog post.