
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@devlln/helm
Advanced tools
Helm sets up the bridge and CLI helpers that keep local Codex sessions reachable from other devices. It handles runtime detection, shell integration, bridge startup, and pairing from one command.
npm install -g @devlln/helm
helm setup
brew tap devlln/helm
brew install devlln/helm/helm
helm setup
npm install -g github:DEVLlN/helm
helm setup
Run the guided setup:
helm setup
helm setup installs the CLI, bridge helpers, runtime shims, shell integration, and binary capture. It also checks local runtimes, can guide Tailscale sign-in, starts the bridge, and prints a pairing QR in the terminal.
Useful setup commands:
helm setup --skip-tailscale
helm setup --no-pairing-qr
helm platforms
helm platforms --json
Helm can detect:
Bridge lifecycle:
helm bridge up
helm bridge pair
helm bridge status
helm bridge down
Runtime helpers:
helm-codex
helm-claude
helm-grok
helm-gemma
helm-qwen
Lower-level helpers:
helm-prototype-up
helm-prototype-status
helm-prototype-down
helm-pairing-qr
Compatibility aliases:
helm up
helm pair
helm status
helm down
If Tailscale is connected, Helm prefers the Tailscale bridge URL automatically when it prints pairing details.
helm setuphelm-gemma and helm-qwen helpersup, pair, status, and downnpm install -g @devlln/helmdevlln/helmnpm install -g github:DEVLlN/helmQuick validation before tagging a release:
scripts/check-public-repo.sh
scripts/test-install-sandbox.sh --smoke --cleanup --no-runtime-start
npm run pack:dry-run
Release details live in docs/DISTRIBUTION.md. Test notes live in TESTING.md.
FAQs
Helm CLI bridge installer and runtime helpers.
The npm package @devlln/helm receives a total of 22 weekly downloads. As such, @devlln/helm popularity was classified as not popular.
We found that @devlln/helm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.