
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@fedify/vocab-tools
Advanced tools
This package contains the utilities for working with Activity Vocabulary objects, which are auto-generated from the IDL.
deno add @fedify/vocab-tools
npm install @fedify/vocab-tools
pnpm add @fedify/vocab-tools
yarn add @fedify/vocab-tools
Run development tasks from the repository root with mise.
The code generator has separate output snapshots for Deno, Node.js, and Bun. When a change affects generated output, update all three from the repository root:
mise run test:update_snapshots
Review and commit every changed snapshot file. Updating only one runtime leaves the other test suites with stale expectations.
A property schema can set extraContext to a context URL. The generated
serializer adds it to its default context when the property's expanded IRI
appears after compaction, including inside nested objects. A caller-provided
context takes precedence. When populated, such a property uses the JSON-LD
processor so context container rules, including @set, are respected.
A type schema can set trustEmbeddedObjects: false when its identifier is
metadata rather than a resource that establishes an origin. Its own
entity-valued accessors then fetch embedded objects with identifiers instead
of trusting a matching origin. Locally constructed values, previously fetched
values, and the explicit crossOrigin: "trust" option retain their usual
behavior. This does not verify id-less embedded objects or establish publishing
authority.
FAQs
Code generator for Activity Vocabulary APIs
The npm package @fedify/vocab-tools receives a total of 13,604 weekly downloads. As such, @fedify/vocab-tools popularity was classified as popular.
We found that @fedify/vocab-tools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.