
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@archstone/provider-rest
Advanced tools
REST provider for Archstone — maps capability input to an HTTP request and maps the response back to a typed, validated result.
REST provider — the only place HTTP appears in the Archstone pipeline. Maps a capability call's typed input to an HTTP request per a binding's connector config, and maps the HTTP response back to a result (or a fail-closed OK/DEGRADED/VIOLATION status) via the binding's response mapping.
Part of Archstone, an open-source
Capability Platform — most users should install
@archstone/cli instead of depending on
this package directly.
Apache-2.0
FAQs
REST provider for Archstone — maps capability input to an HTTP request and maps the response back to a typed, validated result.
The npm package @archstone/provider-rest receives a total of 835 weekly downloads. As such, @archstone/provider-rest popularity was classified as not popular.
We found that @archstone/provider-rest demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.