
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@codellyson/justanotetaker-mcp
Advanced tools
MCP server for Just a Notetaker — lets any MCP client (Claude, etc.) list, create, update, and delete boards and notes on your canvas, drive agent task cards, fill live tables and embeds, and search.
A local stdio MCP server that lets any MCP client (Claude Code, Claude Desktop, etc.) work with your Just a Notetaker canvas — drop research, plans, or task lists onto a board mid-task, reorganize notes, drive agent task cards, and fill live tables and embeds.
It authenticates with a personal API token (jnt_…) and talks to the
deployed API over HTTPS, exposing:
| Tool | What it does |
|---|---|
list_boards | List your canvases (id, name). |
create_board | Create a new board. |
rename_board | Rename a board. |
delete_board | Delete a board and its notes (restorable in-app for 30 days). |
create_note | Create a markdown note on a board (headings, - [ ] tasks, **bold**, links, , …). Board by name or id; x/y optional. |
list_notes | List a board's notes with ids/positions/text/parentId (and, for objects, their live state) — the source of ids for update/delete. |
update_note | Update a note's text, position, or kind by id. |
delete_note | Delete a note by id (restorable in-app for 30 days). |
create_task | Create a task card (agent job) with a queued status. |
update_task | Advance a task card: running, error + message, or done + result — a done task resolves into a plain page note (its result becomes the body). |
create_object | Create a live canvas object: a table (grid the user can also edit by hand) or an embed (live iframe — YouTube, Spotify, Figma, any embeddable URL). |
set_object_state | Replace an object's state — table { columns, rows } or embed { url, title? }. The change shows on the user's canvas within seconds. |
search_notes | Full-text search across your notes. |
In the app, open the command palette (⌘K / Ctrl-K), run API tokens,
name the token, and hit Create. Copy the jnt_… secret — it's shown
once and can't be retrieved again. Revoke tokens from the same panel.
Add to your MCP config (e.g. .mcp.json for Claude Code, or the Desktop config):
{
"mcpServers": {
"justanotetaker": {
"command": "npx",
"args": ["-y", "@codellyson/justanotetaker-mcp"],
"env": {
"JUSTNOTE_TOKEN": "jnt_…",
"JUSTNOTE_API_URL": "https://api.justanotetaker.kreativekorna.com"
}
}
}
}
(Working from the repo instead? pnpm --filter @codellyson/justanotetaker-mcp build
and point command at node <repo>/packages/mcp-server/dist/index.js.)
Then ask your agent to "drop this on my Research board" and it lands as a note. New notes are placed at a random open-ish spot — rearrange on the canvas.
JUSTNOTE_TOKEN (required) — your jnt_… personal token.JUSTNOTE_API_URL (optional) — defaults to the hosted API.FAQs
MCP server for Just a Notetaker — lets any MCP client (Claude, etc.) list, create, update, and delete boards and notes on your canvas, drive agent task cards, fill live tables and embeds, and search.
We found that @codellyson/justanotetaker-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.