
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@aixflow/acoder
Advanced tools
Interactive agentic coding CLI (Ink TUI) backed by your own open-source model endpoint
Interactive agentic coding CLI backed by your own OpenAI-compatible model endpoint — a terminal coding agent like Claude Code / Codex, pointed at a model you host. Rich TUI: streaming responses, live tool activity, markdown output, inline approvals, and file-tree / multi-file edits.
npx @aixflow/acoder setup # one-time: endpoint URL + API key
npx @aixflow/acoder chat # interactive TUI agent
acoder chat)y / n / a(lways) with a diff preview for edits@file to attach a file, / slash commands, Ctrl+C to cancel a turn/mode auto (run freely) · approve (confirm each change) · plan (read-only, proposes)Slash commands: /mode, /cost, /reset, /clear, /help, /exit.
acoder do)acoder do "fix the failing test in parser.js and run the tests" --mode auto
read_file · list_dir · grep · tree · write_file · edit_file · apply_patch (multi-file) · run_bash (incl. git). Reads/searches run freely; writes and commands are gated by your mode.
Read from env vars, ./.env, or ~/.config/acoder/config.env (written by
acoder setup): ACODER_ENDPOINT, ACODER_API_KEY, ACODER_MODEL.
Requires Node ≥ 18. MIT licensed.
FAQs
Interactive agentic coding CLI (Ink TUI) backed by your own open-source model endpoint
The npm package @aixflow/acoder receives a total of 1 weekly downloads. As such, @aixflow/acoder popularity was classified as not popular.
We found that @aixflow/acoder demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.