Episode 157

Shai-Hulud Is Back From the Dead

Next.js 16.3 promises "instant" navigation and faster builds, TanStack keeps shipping like it has something to prove, and Shai-Hulud reminds us npm security remains a cursed timeline.

Full Description

It's been a minute since the last Next.js release, and the team is back again with Next.js 16.3. Highlights of the latest version include: "Instant Navigations" (tools to make server driven app navigations feel snappier), better AI tooling for agents, less memory hungry dev servers, and faster build times. The TanStack team continues to deliver on its ever growing set of libraries with OG library TanStack Table reaching v9.0 and TanStack AI well on its way to v1.0 with offerings like tool calling, reasoning, code sandboxes, memory and more. And on the flip side, a new variant of the Shai-Hulud worm compromised a major package maintainer last week, infecting a bunch of low-level packages around key value storage and caching with over 1B combined monthly downloads. Stay vigilant, folks. For the Lightning News rounds: the Deno v Oracle JavaScript trademark lawsuit continues to drag on as Oracle asks for yet another extension, Anthropic shared how its Claude models also accessed the internet during cybersecurity exercises so as not to be outdone by OpenAI's story of ChatGPT hacking Hugging Face, Google Earth rolled out AI image features that had to be quickly rolled back when they were used to create new nuclear sites on maps and worse, and Sam Altman continues to try and shove AI into folks' everyday lives where it absolutely does not belong. Some things will never change.