CODING JAG - Issue 307

Welcome to the 307th edition of Coding Jag brought to you by TestMu AI!👐

More than 1,300 npm packages turned hostile this week, and together they carry 2 billion downloads a month. The worm behind it, ChainDrop, did not wait around to be executed. Anyone who installed an affected package ran it immediately, laptop or CI runner, before any test could catch it. Open VSX pulled 77 fake extensions, 19 of them quietly logging which repository you had opened.

That wasn't the whole story this week. Microsoft paid a record $20 million to bug hunters and named AI as the reason reports surged. Meta shipped Muse Code, a terminal agent whose background helpers stay alive for a whole session. LangChain published ReviewBench and found the best code review agents recover under a third of what human reviewers catch.

And the TestMu AI State of AI in Testing Survey 2026 is still open: 10 minutes, confidential, findings published back to the community. Tell us how AI is really landing in your testing.

📬 Come across something useful or interesting? Just reply and let's exchange ideas.

News

Massive ChainDrop npm Supply-Chain Attack Infects Hundreds of Packages

08 minChrome-Extensionbleepingcomputer.com

🪱 Bill Toulas at BleepingComputer reports on ChainDrop, a self-propagating worm that hit more than 1,300 npm packages carrying 2 billion monthly downloads. It entered through Keyv's hijacked maintainer account, and a "preinstall" hook ran the payload on npm install, before any test. Aikido counts 868 packages across 1,381 versions.

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

07 minChrome-Extensionthehackernews.com

👁️ Ravie Lakshmanan at The Hacker News covers 77 malicious extensions uploaded to Open VSX between July 26 and August 1, pulled by August 3. Nineteen collected the machine ID, your open repository and the CI system the editor ran inside. Ax Sharma and Cody Nash of Manifold Security traced them.

AI Helps Microsoft Bug Hunters Chase a Record $20M Payday

07 minChrome-Extensiontheregister.com

💰 Connor Jones, cybersecurity reporter at The Register, totals up Microsoft's bounty year: over $20 million paid to 562 researchers, against $17 million to 344 the year before. Microsoft credited the surge in reports to AI-assisted security research. Zero Day Quest added $2.3 million of the total.

Jeff Dean and Other Top AI Researchers Are Leaving Google to Launch Their Own Startup

08 minChrome-Extensiontechcrunch.com

🔬 Lucas Ropek, Senior Writer at TechCrunch, reports that Jeff Dean is leaving Google with Sanjay Ghemawat, Quoc Le and Oriol Vinyals. Their startup, Discovery Loop, is a public benefit corporation aiming to automate experimental loops by running thousands of experiments at once. Dean joined in 1999 as employee number 30.

AI

Introducing Muse Code and Muse Spark 1.2

08 minChrome-Extensionresearch.meta.ai

🤖 Meta has released Muse Code in beta, a terminal coding agent that plans changes, writes code and validates results across large repositories. Its specialized background agents stay active for the whole session rather than spawning per task. It runs on macOS and Linux, powered by Muse Spark 1.2.

Evaluating Code Review Agents With ReviewBench

08 minChrome-Extensionlangchain.com

🔍 Nick Hollon at LangChain built ReviewBench from real pull request feedback in the LangSmith mono-repo: 59 tasks covering 64 issues human reviewers raised. The best runs recovered only about 30%. Precision ran 0.74 to 0.95 while coverage sat at 0.13 to 0.30, so agents are missing issues, not adding noise.

Introducing Shieldstral

07 minChrome-Extensionmistral.ai

🛡️ Mistral has released Shieldstral, a 3B-parameter safety classifier with Apache 2.0 open weights that runs on one 16GB GPU. You hand it a plain-language policy at inference time, no retraining, and get a calibrated safety score. Mistral says it matches open guard models up to seven times its size.

Automation

9 Best AI Red Teaming Tools for LLMs in 2026

09 minChrome-Extensiontestmuai.com

🎯 Sadhvi Singh, Director of Quality Engineering at Brevo, ranks nine AI red teaming tools on the TestMu AI blog, grading them on maintenance, not marketing. Promptfoo leads with 23,809 GitHub stars and daily commits, ahead of Garak at 8,643 and Giskard at 5,726. The framing is OWASP's LLM01, prompt injection.

Cypress 15.20.0 Fixes the Memory Crash Behind Text-Heavy Test Failures

07 minChrome-Extensiongithub.com

🧪 Cypress 15.20.0 is mostly a CI reliability release. A visibility check was serializing element text subtrees so aggressively that it exhausted renderer memory and crashed runs on text-heavy pages. It also repairs session cookies lost from OAuth callbacks inside cy.origin(), and bumps bundled tar to 7.5.21 to clear CVE-2026-59873.

Turn One Giant AI-Generated Pull Request into a Reviewable Stack

08 minChrome-Extensiongithub.blog

🧱 Julia Muiruri, Developer Experiences at GitHub, takes a 1,721-line pull request written by an agent and breaks it into four reviewable layers using the gh-stack CLI extension. The same workflow can be taught to the agent itself. A 1,700-line PR gets rubber-stamped; a four-layer stack gets tested.

TestMu AI State of AI in Testing Survey 2026

10 minChrome-Extensionsurveys.lambdatest.com

📋 The TestMu AI State of AI in Testing Survey 2026 is still open. It takes about 10 minutes, responses stay confidential, and the findings get published back to the community. Tell us how AI is actually landing in your testing, then pass it to a colleague.

Tools

Next.js 16.3

08 minChrome-Extensionnextjs.org

⚡ Next.js 16.3 ships a rare testing primitive. The instant() helper in @next/playwright asserts what is visible during a navigation without waiting for the network, so perceived slowness fails a test. Turbopack disk caching is on by default in next dev, cutting the dev-server memory from 21.5 GB to 2 GB.

IntelliJ IDEA Goes LSP: Java and Kotlin Intelligence Comes to VS Code, Cursor, and Agentic Flows

08 minChrome-Extensionblog.jetbrains.com

☕ Marco Behler at JetBrains introduces "Java & Kotlin by IntelliJ IDEA", a preview VS Code extension carrying IntelliJ's Java and Kotlin intelligence into VS Code and Cursor over LSP. Read the licensing line first: free during preview, but each build renews a 30-day evaluation, and Ultimate is required afterward.

Video & Podcast

Playwright With AI: How to Automate Tests Without Shipping AI Slop with Andrew Knight

08 minChrome-Extensiontestguild.com

🎤 Joe Colantonio hosts Andrew Knight, the Automation Panda and now a senior director at Cycle Labs. Knight describes six people delivering the biggest release quarter in his company's history using AI coding agents, spec-driven development and Playwright. His line for the era: AI coding tools are the new compiler.

Built-in Dictation in VS Code: Code at the Speed of Thought

07 minChrome-Extensionyoutube.com

🗣️ James Montemagno demos built-in dictation on the official VS Code channel, shipped in version 1.131 with no extension required. Speak into chat inputs, text editors and the integrated terminal, and transcription runs on a private offline model, so your audio never leaves the machine. Optional AI cleanup strips filler words.

Events

TestMu Conf 2026 | Agentic Engineering & QA Summit

07 minChrome-Extensiontestmuai.com

🎤 Under two weeks to go. TestMu Conf runs August 19 to 21, virtual and completely free, with 80 sessions and 100+ speakers on agentic engineering and QA, and 75K registrations expected from 120+ countries. Keynotes come from Replit's CTO Luis Hector Chavez, Microsoft's Francesca Lazzeri and Entire's CEO Thomas Dohmke.

GitHub Universe 2026

07 minChrome-Extensiongithubuniverse.com

🎤 GitHub Universe 2026 runs October 28-29 at Fort Mason Center in San Francisco, with an optional day of learning. In-person passes are $1,099 at early bird against $1,399 regular, dropping to $879 each on orders of four or more. The virtual pass is free. Early bird closes August 20.