
Loss Selling (not me)
Got DMd with this. Are these guys legit? Are the prices decent? Cuz I’ve been wanting to buy losses to farm up merits.

Got DMd with this. Are these guys legit? Are the prices decent? Cuz I’ve been wanting to buy losses to farm up merits.
When accepted and in as DTO, are SIP qualifying certs paid for or reimbursed by the DoS? If yes, what about potential paid prep courses for them?
Hi everyone,
I’m looking for a second opinion from people with more experience in malware analysis and npm supply-chain attacks.
I hired a freelance developer for a small feature. After only a couple of hours, he asked us to review his initial commit. During the review, my lead developer noticed a recently published npm package that seemed out of place. Digging further, we found that it pulls in another package from the same author containing heavily obfuscated code.
This is not my repository or package. It’s code that was submitted to me by a contractor. I’m only sharing it because I’m trying to determine whether we’re dealing with a legitimate dependency, AI-generated garbage, or an actual malicious supply-chain attack.
Our current observations:
It’s entirely possible we’re being overly cautious, so I’d appreciate experienced eyes on it.
Repository: https://github.com/ist89/backtesting-project
If anyone is willing to review the dependency chain or explain whether this is actually malicious (or just looks suspicious), I’d really appreciate it.
Thanks.
Passed DTOT about 3 weeks ago. Piece of paper said written exercise is next. Just wondering how long it usually takes before it pops up? I'm in no rush and I'm 100% aware that the whole process is long and arduous. Just figured some people may be able to share how long they waited until after DTOT to continue the process.