
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@forestrie/mandate-ui-e2e-kit
Advanced tools
Reusable Playwright fixtures and BFF mocks for mandate UI e2e (ARC-0024 Layer 1)
Reusable Playwright fixtures and coordinator BFF mocks for mandate UI browser e2e. Published for cross-repo consumers per devdocs ARC-0024 and ADR-0041.
Published to public npmjs with SLSA provenance (FOR-361) — tokenless
install, no .npmrc scope mapping. The @forestrie scope maps to one
registry per consumer, and consumers such as forestrie/system-testing
install this kit alongside npmjs-only @forestrie/canopy-e2e-kit, so the kit
publishes to npmjs too.
pnpm add @forestrie/mandate-ui-e2e-kit @playwright/test
# Peer: coordinator types from mandate at a pinned commit
pnpm add "github:forestrie/mandate#<sha>&path:packages/libs/coordinator-types"
installCoordinatorMocks(page, options?) — browser route mocks for BFF + authloginWithMockPrivy, loadPending — Privy OTP login helperssamplePendingEntry, samplePendingEntries, E2E_AUTH_LOG_ID, …test, expect — Playwright fixture with consolePage + mocks optionpnpm --filter @forestrie/mandate-ui-e2e-kit build
pnpm --filter @forestrie/mandate-ui-e2e-kit test
Hermetic runner @mandate/ui-e2e depends on this package via workspace:*.
FAQs
Reusable Playwright fixtures and BFF mocks for mandate UI e2e (ARC-0024 Layer 1)
The npm package @forestrie/mandate-ui-e2e-kit receives a total of 14 weekly downloads. As such, @forestrie/mandate-ui-e2e-kit popularity was classified as not popular.
We found that @forestrie/mandate-ui-e2e-kit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.