
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@claudexor/review
Advanced tools
Deterministic gates, cross-family review, finding revalidation, route proof, convergence, readiness-debt.
Internal package of Claudexor — Deterministic gates, cross-family review, finding revalidation, route proof, convergence, readiness-debt.
Published as part of the Claudexor toolchain; it follows the monorepo's
lockstep version and has no separate semver contract. Use the claudexor
CLI (or @claudexor/cli) as the supported entry point.
FAQs
Deterministic gates, cross-family review, finding revalidation, route proof, convergence, readiness-debt.
The npm package @claudexor/review receives a total of 768 weekly downloads. As such, @claudexor/review popularity was classified as not popular.
We found that @claudexor/review demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.