
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@edgestore/sdk
Advanced tools
Official low-level TypeScript SDK for the EdgeStore API.
The SDK is server-only and uses EdgeStore API v2. Generated OpenAPI types stay internal while the package exposes a stable, resource-oriented public API.
Operation and field documentation is generated from the pinned OpenAPI schema; SDK-specific behavior is documented on the handwritten public facade.
import { createEdgeStoreSdk } from '@edgestore/sdk';
const sdk = createEdgeStoreSdk({
credentials: {
accessKey: process.env.EDGESTORE_ACCESS_KEY!,
secretKey: process.env.EDGESTORE_SECRET_KEY!,
},
});
const result = await sdk.runtime.uploads.upload({
bucket: 'documents',
source: pdfBlob,
fileName: 'invoice.pdf',
metadata: { invoiceId: 'invoice-123' },
signal,
onProgress: ({ percentage, phase }) => console.log(phase, percentage),
});
Project credentials expose runtime resources for their current project.
Management tokens expose management resources and runtime calls that can use
an explicit project selector or an eagerly scoped client:
const management = createEdgeStoreSdk({
credentials: { token: process.env.EDGESTORE_MANAGEMENT_TOKEN! },
});
const project = management.runtime.forProject('project-id');
const files = await project.files.search({ bucket: 'documents' });
Use apiUrl when targeting a compatible API v2 deployment. Its value is the
complete v2 URL, such as https://api.example.com/v2.
Use runtime.files.generateSignedReadUrls for protected runtime reads and
management.files.generateAccessUrls when management code needs readable URLs
for public or protected files.
Common runtime inputs and results are exported as named types. Types for any other operation can be derived from the public SDK interfaces:
import type { ManagementEdgeStoreSdk } from '@edgestore/sdk';
type CreateProject =
ManagementEdgeStoreSdk['management']['projects']['create'];
type CreateProjectInput = Parameters<CreateProject>[0];
type CreateProjectOutput = Awaited<ReturnType<CreateProject>>;
The high-level upload helper supports automatic multipart selection, bounded parallelism, retries, progress, abort signals, cancellation, and processing polling. Lower-level upload lifecycle methods are also available.
See the EdgeStore documentation for runtime, management, error-handling, and custom transport examples.
FAQs
Official low-level TypeScript SDK for the EdgeStore API
The npm package @edgestore/sdk receives a total of 329 weekly downloads. As such, @edgestore/sdk popularity was classified as not popular.
We found that @edgestore/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.