
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@coder/cmux
Advanced tools

A desktop application for parallel agentic development.
Here are some specific use cases we enable:
code-review, refactor, and new-featurecmux away from main worksonnet-4-*, gpt-5-*, opus-4-*)cmux has a custom agent loop, but, we are heavily inspired by Claude Code in our
UX. You'll find familiar features like Plan/Exec mode, VIM inputs, /compact and new ones
like opportunistic compaction and mode prompts.
[!WARNING]
cmux is in a Preview state. You will encounter bugs and performance issues. It's still possible to be highly productive. We are using it almost exclusively for our own development.
Download pre-built binaries from the releases page for macOS and Linux.
Integrated code-review for faster iteration:
Agents report their status through the sidebar:
Git divergence UI keeps you looped in on changes and potential conflicts:
Mermaid diagrams make it easier to review complex proposals from the Agent:
Project secrets help split your Human and Agent identities:
Stay looped in on costs and token consumption:
Opportunistic compaction helps keep context small:
TODO lists keep you informed on the agent's plan:
See the documentation for more details.
See AGENTS.md for development setup and guidelines.
Copyright (C) 2025 Coder Technologies, Inc.
This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as published by the Free Software Foundation, version 3 of the License.
See LICENSE for details.
FAQs
cmux - coder multiplexer
The npm package @coder/cmux receives a total of 8 weekly downloads. As such, @coder/cmux popularity was classified as not popular.
We found that @coder/cmux demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.