
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@featureflip/js
Advanced tools
Server-side JavaScript/TypeScript SDK for Featureflip - evaluate feature flags locally with near-zero latency.
npm install @featureflip/js
import { FeatureflipClient, createNodePlatform } from '@featureflip/js';
const client = FeatureflipClient.get(
{ sdkKey: 'your-sdk-key', baseUrl: 'https://eval.featureflip.io' },
createNodePlatform(),
);
await client.waitForInitialization();
const enabled = client.boolVariation('my-feature', { user_id: '123' }, false);
if (enabled) {
console.log('Feature is enabled!');
}
await client.close();
Singleton by construction.
FeatureflipClient.get()is the only way to obtain a client. Callingget()more than once with the same SDK key returns handles pointing at one shared underlying client — the factory is refcounted, so closing a handle only shuts down the shared core when the last handle is closed. This makes the SDK safe to call from per-request handlers and DI containers without leaking SSE connections.
const client = FeatureflipClient.get(
{
sdkKey: 'your-sdk-key',
baseUrl: 'https://eval.featureflip.io', // Evaluation API URL
streaming: true, // Use SSE for real-time updates (default)
pollInterval: 30000, // Polling interval in ms if streaming=false
flushInterval: 30000, // Event flush interval in ms
flushBatchSize: 100, // Events per batch
initTimeout: 10000, // Max ms to wait for initialization
maxStreamRetries: 5, // SSE retries before falling back to polling
},
createNodePlatform(),
);
const context = { user_id: '123', email: 'user@example.com' };
// Boolean flag
const enabled = client.boolVariation('feature-key', context, false);
// String flag
const tier = client.stringVariation('pricing-tier', context, 'free');
// Number flag
const limit = client.numberVariation('rate-limit', context, 100);
// JSON flag
const config = client.jsonVariation('ui-config', context, { theme: 'light' });
const detail = client.variationDetail('feature-key', { user_id: '123' }, false);
console.log(detail.value); // The evaluated value
console.log(detail.reason); // "RuleMatch", "Fallthrough", "FlagDisabled", etc.
console.log(detail.ruleId); // Rule ID if reason is "RuleMatch"
// Track custom events
client.track('checkout-completed', { user_id: '123' }, { total: 99.99 });
// Record an identify event for analytics (does not affect flag evaluation)
client.identify({ user_id: '123', email: 'user@example.com', plan: 'pro' });
// Force flush pending events
await client.flush();
Use forTesting() to create a client with predetermined flag values -- no network calls.
const client = FeatureflipClient.forTesting({
'my-feature': true,
'pricing-tier': 'pro',
});
client.boolVariation('my-feature', {}, false); // true
client.stringVariation('pricing-tier', {}, 'free'); // 'pro'
client.boolVariation('unknown', {}, false); // false (default)
forTesting() factory for deterministic unit testsApache-2.0
FAQs
JavaScript/TypeScript SDK for Featureflip
We found that @featureflip/js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.