1028: Cloudflare Wallets artwork

1028: Cloudflare Wallets

Syntax - Tasty Web Development Treats

August 10, 2026

Cloudflare is rolling out crypto wallets with claimable handles as identity, and a real React compiler finally landed for regular hooks-based code. Plus: OpenAI's pricing war, Vue Vapor benchmarks, GitHub's new npm malware scanning, and an active supply chain attack hitting 868 packages.
Speakers: Wes Bos, Scott Tolinski, CJ

Topics: Technology, News, Tech News

**Wes Bos** (0:00)
What's up, everybody? Thanks for tuning in. This is a Syntax livestream. Tons of news going on this week. We've got Cloudflare Wallets was just announced. We're going to talk about what that is and why you might be interested in. Another Shyhaloot attack going down right now. Scott's going to fill us in. Don't NPM install anything until you hear what Scott has to say about that.
A real React compiler. Last week, we talked about the new React compiler, but CJ's got a new React compiler. AI pricing wars have started. OpenAI is discounting a lot of their models right now. Plus, a whole bunch of it. If you have anything you'd like us to cover, hit it down and throw it down in the chat, and we'll be sure to cover it. What's up, everybody? How are you doing?

**Scott Tolinski** (0:41)
Oh, doing good. How are you doing, Wes?

**Wes Bos** (0:43)
Yeah.

**Scott Tolinski** (0:44)
You get wormed today?

**Wes Bos** (0:46)
Not yet, unfortunately, but unfortunately.

**Scott Tolinski** (0:51)
Not yet, unfortunately.
Wes wanted to get wormed. I got it. News at 11 Yes.

**Wes Bos** (0:59)
Yes.

**Scott Tolinski** (0:59)
Yes. Dewormed. Yes, we need to get dewormed. Well, today there is a new Shyhalood attack going down and one which has already compromised 868 packages carrying over two billion monthly installs.
So the seems like the main package that was compromised. It started with this Keev package, which I haven't used. Have you guys used this one?

**Wes Bos** (1:29)
No, I don't believe so. But you never know if it's all the way down the dependency tree.

**CJ** (1:33)
Dependency.

**Scott Tolinski** (1:34)
Yes. It's a key value and cacheable.
It's a key value library that it seems like it has quite a lot of people using this. So this is a library that well was compromised and now the worm is doing worm stuff and a ton of other packages have been compromised. So the folks, the advice that we always give you on these worms is that you should be setting your packages not to install things that have not been available for at least a day or so. PNPM, NPM, they all have this feature.
So PNPM has it by default. Easiest solution is to just use PNPM. It's a great packaging manager in the first place. But just scrolling through this list, it's just another one of these big old worms that's coming up to slurp up all of your stuff, which is really the thing here is that it's trying to grab your ENV variables, it's trying to grab all kinds of stuff. Again, a pre-install hook fires on NPM install and drops a Stealer that sweeps NPM, GitHub, AWS, Kubernetes, and Vault secrets and then spreads to more maintainers. This is the same type of worm that we've seen over and over and over again. I think this is like the fifth or fourth shy halloo that we've seen recently.

**CJ** (3:02)
This year alone, yeah. Last seven months.

**Scott Tolinski** (3:05)
So be careful out there folks. There's a CSV of a ton of packages that have been hit from this bad boy.

**Wes Bos** (3:13)
One interesting thing about all of these attacks is that you're not hearing these stories of there was an attack and these Bitcoin wallets were drained immediately. You're often hearing there was all of these attacks and then we don't often hear too much follow up of like what actually happened. And shout out on Friday, I'm releasing a video on the like black market of AI tokens. And what I'm learning is that a lot of these hacks, they're they're stealing your AI tokens or they're stealing access to your to whatever app you have. And then they are just just stealing enough that you won't notice it. And they're selling those on the black market. So on Friday, I have a video going live. Make sure you catch it.
Where I dive into, I actually go ahead and buy some of these black market tokens that are often stolen in these attacks.

**Scott Tolinski** (4:03)
Wow.

**CJ** (4:03)
Nice.

**Scott Tolinski** (4:04)
Yeah, I'm really stoked to see that.

**CJ** (4:06)
Me too. And I'm working on a video that will show you how to not run code on your computer, potentially to stop you from being a victim of one of these attacks as well. So we got you covered here at Syntax.

**Scott Tolinski** (4:16)
Yeah, we got you covered. And I'm actually making a video on mental health and AI coding, folks. So I'm running a survey right now and I'll post this in the chat. If you could fill this out, it is quick. It's a breezy five questions. Actually, I lied. It's six questions, but one of which is just how many agents are you running? So we're doing a deep mental health survey here, really super fast. You could go ahead and fill that out. That would make the results a lot better. And the video is coming soon on Syntax. So just that video is going to be mental, Scott.

71 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID