
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@commonninja/node-sdk
Advanced tools
// NPM
npm i @commonninja/node-sdk
// Yarn
yarn add @commonninja/node-sdk
import { CommonNinja } from '@commonninja/node-sdk';
const client = new CommonNinja({
appId: process.env.COMMONNINJA_APP_ID,
appSecret: process.env.COMMONNINJA_APP_SECRET,
accessToken: req.query.token,
env: CommonNinja.envs.production,
});
// Get shop products, filter by category
const { data, success, message } = await client.ecommerce.getProducts({
category: '1',
});
// Get shop orders
const { data, success, message } = await client.ecommerce.getOrders();
// Get shop customers with pagination parameters
const { data, success, message } = await client.ecommerce.getCustomers({
limit: 5,
page: 1,
});
// Get user details
const { data, success, message } = await client.user.getDetails();
// Get connect to platform screen url
const connectUrl = client.auth.getConnectUrl();
// Get Shopify authentication url
const redirectUrl = client.auth.getAuthenticationUrl('shopify');
// Validate an incoming webhook message from Common Ninja
client.webhooks.validateWebhook(req);
Learn more about the different APIs in our official docs.
FAQs
Common Ninja SDK for NodeJS
The npm package @commonninja/node-sdk receives a total of 67 weekly downloads. As such, @commonninja/node-sdk popularity was classified as not popular.
We found that @commonninja/node-sdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.