
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@agents-npm-packages/turbolint
Advanced tools
Ultra-fast JavaScript/TypeScript linter CLI implemented in Rust on top of Oxc.
npm install @agents-npm-packages/turbolint
Then run the published binary:
turbolint ./src
cargo build --release
./target/release/turbolint ./src
The npm package ships the same command name and falls back to a local Cargo build if a native binary is not already present.
TurboLint recursively scans .js, .jsx, .ts, and .tsx files while ignoring
node_modules and .git. It exits with 1 when violations are found and 0
when the tree is clean.
--config PATH: load rule toggles and extra ignore patterns from a JSON file--ignore-file PATH: load extra ignore globs from a text file--json: emit structured JSON output with scan stats and violations--fix: apply safe autofixes for no-var by rewriting var to letThe repo also ships a static marketing/docs site in site/
with dark shadcn-inspired styling, command examples, and a product overview.
The live hostname is turbolint.ideatr.dev; GitLab hosts the public source and
docs, while Vercel serves the live site.
no-eval: flags eval(...)no-var: flags var declarationsno-console-log: flags console.log(...)Only no-var is auto-fixable. The other rules are report-only by design.
ignore crate's parallel walker
instead of a single recursive loop.gitlab.com/arjunkshah/turbolintturbolint.ideatr.devsite/docs/FAQs
Ultra-fast JavaScript/TypeScript linter CLI
We found that @agents-npm-packages/turbolint demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.