
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@fairseal/game
Advanced tools
Game API scaffold (v0.1 ALPHA — offline beacon, not production-ready. Real drand integration in v0.2)
⚠️ v0.1 ALPHA — Offline beacon only. NOT production-ready. This version uses a simulated beacon (
crypto.randomBytes), not real drand. Verification proves internal hash consistency only — it does NOT prove the operator couldn't have chosen a favorable seed. Real drand integration comes in v0.2. Do not use v0.1 for production provably fair claims.
Game API scaffold for RGS studios — Seed Commitment Model.
npm install @fairseal/game
import { createSession, deriveSpin, deriveSubResult, closeSession, verifySession, mapEntropy } from '@fairseal/game';
// Create a provably fair session
const session = await createSession({
mode: 'provably-fair',
serverSeed: 'your-secret-seed',
clientSeed: 'player-seed',
gameId: 'my-slot-game',
paytableHash: 'abc123',
});
// Derive spin results (pure computation — zero latency)
const spin = deriveSpin(session, 0);
console.log(spin.entropy); // Use to derive game result
// Free spins, cascades, bonuses — unlimited sub-paths
const freeSpin = deriveSubResult(session, 0, 'freespin', 0);
// Close session and get verifiable receipt
const receipt = await closeSession(session);
const result = verifySession(receipt);
console.log(result.valid); // true
provably-fair (Mode A): Full player verifiability. Client seed participates in derivation.audit-only (Mode B): GLI-19 safe. Client seed recorded as witness only.| Function | Description |
|---|---|
createSession(config) | Create a new game session with committed seed |
awaitSession(session) | Wait for beacon resolution (0-3s) |
deriveSpin(session, index) | Derive spin result — pure HMAC, zero latency |
deriveSubResult(session, parent, type, index) | Derive sub-event (free spin, cascade, etc.) |
mapEntropy(entropy, range) | Map 256-bit entropy to [0, range) |
closeSession(session) | Close session, reveal seed, generate receipt |
rotateClientSeed(session, newSeed) | Atomic seed rotation (Mode A only) |
verifySession(receipt) | Client-side receipt verification |
computeMerkleRoot(leaves) | Merkle tree construction |
See RFC-001 for full specification.
MIT
FAQs
Game API scaffold (v0.1 ALPHA — offline beacon, not production-ready. Real drand integration in v0.2)
The npm package @fairseal/game receives a total of 21 weekly downloads. As such, @fairseal/game popularity was classified as not popular.
We found that @fairseal/game demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.