
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@empiricalrun/cli
Advanced tools
[](https://npmjs.com/package/@empiricalrun/cli) [](https://discord.gg/NeR6jj8dw9)
Empirical is the fastest way to test different LLMs, prompts and other model configurations, across all the scenarios that matter for your application.
With Empirical, you can:
Watch demo video | See all docs
Empirical bundles together a CLI and a web app. The CLI handles running tests and the web app visualizes results.
Everything runs locally, with a JSON configuration file, empiricalrc.json.
Required: Node.js 20+ needs to be installed on your system.
In this example, we will ask an LLM to parse user messages to extract entities and
give us a structured JSON output. For example, "I'm Alice from Maryland" will
become "{name: 'Alice', location: 'Maryland'}".
Our test will succeed if the model outputs valid JSON.
Use the CLI to create a sample configuration file called empiricalrc.json.
npx @empiricalrun/cli init
cat empiricalrc.json
Run the test samples against the models with the run command. This step requires
the OPENAI_API_KEY environment variable to authenticate with OpenAI. This
execution will cost $0.0026, based on the selected models.
npx @empiricalrun/cli run
Use the ui command to open the reporter web app and see side-by-side results.
npx @empiricalrun/cli ui
Edit the empiricalrc.json file to make Empirical work for your use-case.
FAQs
[](https://npmjs.com/package/@empiricalrun/cli) [](https://discord.gg/NeR6jj8dw9)
The npm package @empiricalrun/cli receives a total of 67 weekly downloads. As such, @empiricalrun/cli popularity was classified as not popular.
We found that @empiricalrun/cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.