HN Buddy

Daily digest of top Hacker News posts and comments

Subscribe to the HN Buddy Daily Digest

Your email will only be used for the HN Buddy Daily Digest. I will not share it with anyone.

HN Buddy Daily Digest

Tuesday, March 31, 2026

Hey buddy,

Man, you wouldn't believe the stuff that was blowing up on Hacker News yesterday, Tuesday, March 31st. Had to give you a quick rundown.

Big AI Leaks & Security Messes

First off, the biggest thing was this huge leak from Claude Code. Apparently, their actual source code got out! Someone found it through a map file in their NPM registry. Crazy, right? Then there was a follow-up article that dug into the leaked code, showing they had all these internal "fake tools," "frustration regexes," and even an "undercover mode" in there. One of the comments was hilarious, someone just said "I have and I hated it" – totally random, it was actually about a music genre, but it popped up in the top comments for the leak and made me chuckle. Another comment talked about how the code even detected "frustration" from users. Wild stuff.

And speaking of NPM, remember Axios? Yeah, that popular JavaScript library? Well, it got compromised on NPM. Malicious versions were dropping a remote access trojan! Super nasty supply chain attack. One of the comments said the maintainer replied, basically saying someone just "bombed the repo through the API." It's making everyone trust package management even less, which, fair enough. You can read more about it here.

Oracle's Massive Cuts

Then, get this, Oracle just slashed 30,000 jobs. Thirty THOUSAND! That's a huge number. There was a lot of talk in the comments about how people get so tied to their jobs financially, and someone even brought up a scandal in Sweden where Oracle's Millennium system totally crashed and burned at hospitals. Yikes. Check out the story here.

Space and AI Performance

On the space front, there was an article arguing that Artemis II is not safe to fly. Pretty bold claim, but it sparked a lot of discussion about the risks of complex systems and "normal accidents." You can read the full take here.

And for the tech nerds, Ollama is now using Apple's MLX on Apple Silicon. This means if you're running local LLMs on your Mac, they should be way faster now, especially for longer conversations. People in the comments were talking about how LLMs need tons of fast memory, and how RAM prices always go through these "pig cycles." More details here.

GitHub & Copilot Drama

Remember that whole thing with GitHub Copilot trying to put ads in pull requests? Well, good news, they backed down! After a huge backlash, they killed those ads. Thank goodness. People were pretty mad, and it led to some interesting discussions about capitalism vs. state-funded research in the comments. The Register has the story here.

And to top off the Copilot news, Microsoft's terms of use for it apparently now say Copilot is "for entertainment purposes only." LOL. One commenter compared it to a Magic 8 Ball or Tarot cards. So much for professional coding assistance, eh? You can find Microsoft's official terms here.

Anyway, just thought you'd wanna hear about it. Talk soon!

All Stories from Today

Claude Code's source code has been leaked via a map file in their NPM registry (twitter.com)

Axios compromised on NPM – Malicious versions drop remote access trojan (www.stepsecurity.io)

The Claude Code Source Leak: fake tools, frustration regexes, undercover mode (alex000kim.com)

Oracle slashes 30k jobs (rollingout.com)

Artemis II is not safe to fly (idlewords.com)

Ollama is now powered by MLX on Apple Silicon in preview (ollama.com)

GitHub backs down, kills Copilot pull-request ads after backlash (www.theregister.com)

Microsoft: Copilot is for entertainment purposes only (www.microsoft.com)

GitHub's Historic Uptime (damrnelson.github.io)

Universal Claude.md – cut Claude output tokens (github.com)

OkCupid gave 3M dating-app photos to facial recognition firm, FTC says (arstechnica.com)

OpenAI closes funding round at an $852B valuation (www.cnbc.com)

Open source CAD in the browser (Solvespace) (solvespace.com)

Claude Code users hitting usage limits 'way faster than expected' (www.theregister.com)

Google's 200M-parameter time-series foundation model with 16k context (github.com)

A dot a day keeps the clutter away (scottlawsonbc.com)

Why the US Navy won't blast the Iranians and 'open' Strait of Hormuz (responsiblestatecraft.org)

Tell HN: Chrome says "suspicious download" when trying to download yt-dlp (news.ycombinator.com)

Show HN: 1-Bit Bonsai, the First Commercially Viable 1-Bit LLMs (prismml.com)

Slop is not necessarily the future (www.greptile.com)

MiniStack (replacement for LocalStack) (ministack.org)

Italy blocks US use of Sicily air base for Middle East war (www.politico.eu)

Cohere Transcribe: Speech Recognition (cohere.com)

Combinators (tinyapl.rubenverg.com)

Show HN: Postgres extension for BM25 relevance-ranked full-text search (github.com)

U.S. stocks are set to deliver their worst quarter in nearly four years (www.wsj.com)

GitHub Monaspace Case Study (lettermatic.com)

I traced my traffic through a home Tailscale exit node (tech.stonecharioteer.com)

Nobody is coming to save your career (alifeengineered.substack.com)

Ordinary Lab Gloves May Have Skewed Microplastic Data (nautil.us)