
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@agentbadge/bstock-tracker
Advanced tools
bStock delta tracker engine — Binance tokenized stocks vs underlying US equities (Finnhub/Alpaca), delta computation, alerts (EPIC-141)
Delta tracker engine for Binance tokenized stocks (bStocks) vs underlying
US equities (EPIC-141). Pure logic package — no server imports; consumed by
hackathon/server wiring and the standalone Fly.io deployment.
delta% = (bStockMid − underlyingMid × multiplier) / (underlyingMid × multiplier) × 100
multiplier comes from Binance /sapi/v1/equity/market/tokenized-assets
and is NOT always 1 (e.g. NVDAB = 1.00077822).
Required: BINANCE_BSTOK_API_KEY, BINANCE_BSTOK_API_SECRET,
FINNHUB_API_KEY.
Optional: ALPACA_API_KEY + ALPACA_API_SECRET (fallback provider),
TELEGRAM_BOT_BSTOK_TOKEN (+ TELEGRAM_BSTOK_CHAT_ID,
TELEGRAM_BSTOK_BATCH_MS), MCP_AGENT_TOKENS (comma-separated bearers),
threshold overrides BSTOCK_DELTA_ALERT_PCT (0.5), BSTOCK_STALE_MS
(15000), BSTOCK_REST_POLL_MS (30000), BSTOCK_OFF_MARKET_ALERT_MS
(10800000), BSTOCK_ROLLING_WINDOW_POINTS (1440).
bun run build — tsc → dist/bun test / bunx vitest run --run — vitestFAQs
bStock delta tracker engine — Binance tokenized stocks vs underlying US equities (Finnhub/Alpaca), delta computation, alerts (EPIC-141)
The npm package @agentbadge/bstock-tracker receives a total of 48 weekly downloads. As such, @agentbadge/bstock-tracker popularity was classified as not popular.
We found that @agentbadge/bstock-tracker demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.