
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@featureflip/browser
Advanced tools
Framework-agnostic browser SDK for evaluating Featureflip feature flags.
npm install @featureflip/browser
import { FeatureflipClient } from '@featureflip/browser';
const client = FeatureflipClient.get({
clientKey: 'your-client-sdk-key',
});
await client.initialize();
const showBanner = client.boolVariation('show-banner', false);
Singleton by construction.
FeatureflipClient.get()is the only way to obtain a client — the public constructor was removed in v2.0. Callingget()more than once with the sameclientKeyreturns handles pointing at one shared underlying client (refcounted). This makes framework bindings, React StrictMode double-mounts, and per-component construction all harmless — they all resolve to one SSE connection and one flag store per key.
FeatureflipClient.get(config)FeatureflipClient.get(config: FeatureflipClientConfig): FeatureflipClient
Returns a client for the given client key. The first call constructs and registers a shared core; subsequent calls with the same key return a new handle pointing at the cached core. When the last handle for a key is closed, the core shuts down and is removed from the cache.
| Option | Type | Default | Description |
|---|---|---|---|
clientKey | string | (required) | Client SDK key from your project settings |
baseUrl | string | https://eval.featureflip.io | Evaluation API base URL |
context | Record<string, unknown> | {} | Initial evaluation context (user attributes) |
streaming | boolean | true | Enable SSE streaming for real-time updates |
initTimeout | number | 10000 | Timeout in ms for the initial evaluate request |
initialize(): Promise<void>Fetches all flag values from the server. Must be called before reading variations. Opens an SSE streaming connection if streaming is enabled.
boolVariation(key: string, defaultValue: boolean): booleanReturns a boolean flag value, or defaultValue if the flag is missing or not a boolean.
stringVariation(key: string, defaultValue: string): stringReturns a string flag value, or defaultValue if the flag is missing or not a string.
numberVariation(key: string, defaultValue: number): numberReturns a number flag value, or defaultValue if the flag is missing or not a number.
jsonVariation<T>(key: string, defaultValue: T): TReturns a flag value cast to T, or defaultValue if the flag is missing.
identify(context: Record<string, unknown>): Promise<void>Re-evaluates all flags with a new context (e.g., after login). Emits change events for any flags whose values changed.
await client.identify({ user_id: '123', plan: 'pro' });
on(event: EventType, handler: EventHandler): voidSubscribe to events.
'ready' -- fired after initialize() completes'change' -- fired when flag values change (receives a FlagChanges object)'error' -- fired on streaming or network errorsclient.on('change', (changes) => {
console.log('Flags changed:', changes);
});
off(event: EventType, handler: EventHandler): voidUnsubscribe from events.
close(): voidDecrements the refcount on the shared core. When the last handle for a given client key is closed, the shared core closes the SSE connection and removes itself from the factory cache. Double-close on the same handle is a no-op.
Use FeatureflipClient.forTesting() to create a client with predetermined flag values -- no network calls.
const client = FeatureflipClient.forTesting({
'show-banner': true,
'button-color': 'blue',
});
client.boolVariation('show-banner', false); // true
client.stringVariation('button-color', 'red'); // 'blue'
Apache-2.0
FAQs
Browser SDK for Featureflip - framework-agnostic feature flag client
The npm package @featureflip/browser receives a total of 28 weekly downloads. As such, @featureflip/browser popularity was classified as not popular.
We found that @featureflip/browser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.