
Research
/Security News
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
@devlln/helm
Advanced tools
Helm sets up the bridge and CLI helpers that keep local Codex sessions reachable from other devices. It handles runtime detection, shell integration, bridge startup, and pairing from one command.
npm install -g @devlln/helm
helm setup
brew tap devlln/helm
brew install devlln/helm/helm
helm setup
npm install -g github:DEVLlN/helm
helm setup
Run the guided setup:
helm setup
helm setup installs the CLI, bridge helpers, runtime shims, shell integration, and binary capture. It also checks local runtimes, can guide Tailscale sign-in, starts the bridge, and prints a pairing QR in the terminal.
Useful setup commands:
helm setup --skip-tailscale
helm setup --no-pairing-qr
helm platforms
helm platforms --json
Published npm and Homebrew installs check for bridge updates automatically while the launchd bridge service is running. Local git checkouts do not auto-update unless HELM_BRIDGE_AUTO_UPDATE=1 is set.
Manual update commands:
helm update
helm update --dry-run
helm update --method homebrew
helm update --method npm
helm update --method git
Helm can detect:
Bridge lifecycle:
helm bridge up
helm bridge pair
helm bridge status
helm bridge down
Runtime helpers:
helm-codex
helm-claude
helm-grok
helm-gemma
helm-qwen
Lower-level helpers:
helm-prototype-up
helm-prototype-status
helm-prototype-down
helm-bridge-service install
helm-pairing-qr
Compatibility aliases:
helm up
helm pair
helm status
helm down
If Tailscale is connected, Helm prefers the Tailscale bridge URL automatically when it prints pairing details.
Helm is also being built as native iOS and macOS apps. They are not included in the public install yet, but they are planned as the main user-facing surfaces for the bridge.
Coming soon.
Features already working in the development app:
Planned before the public iOS release:
Coming soon.
Features already working in the development app:
Planned before the public macOS release:
helm setuphelm-gemma and helm-qwen helpersup, pair, status, and downnpm install -g @devlln/helmdevlln/helmnpm install -g github:DEVLlN/helmFAQs
Helm CLI bridge installer and runtime helpers.
The npm package @devlln/helm receives a total of 22 weekly downloads. As such, @devlln/helm popularity was classified as not popular.
We found that @devlln/helm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.

Research
/Security News
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.

Security News
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.