Sources
AI Reddit — 2026-06-08#
The Buzz#
The single most alarming shift today is a massive, active supply chain attack targeting Claude Code and VSCode users. Malware planted by the TeamPCP group in compromised npm packages is silently harvesting developer credentials and persisting in local settings files, even wiping home directories if access is revoked. On a more optimistic technical front, Xiaomi shocked the community by announcing their MiMo-V2.5-Pro MoE model achieved over 1,000 tokens per second on standard, commodity 8-GPU clusters by combining FP4 quantization, DFlash speculative decoding, and TileRT kernels.