
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@frontmcp/utils
Advanced tools
Shared utility functions for FrontMCP - string manipulation, URI handling, path utilities, and more
Shared utility functions for the FrontMCP ecosystem.
Internal package. Used by
@frontmcp/sdkand other@frontmcp/*libraries — most users do not need to install this directly.
npm install @frontmcp/utils
Naming — splitWords, toCase, shortHash, ensureMaxLen, idFromString for string manipulation and case conversion
URI — isValidMcpUri, extractUriScheme, parseUriTemplate, matchUriTemplate, expandUriTemplate (RFC 3986 / RFC 6570)
Path — trimSlashes, joinPath for URL path operations
Content — sanitizeToJson, inferMimeType for safe serialization and MIME detection
HTTP — validateBaseUrl for URL validation and normalization
Crypto — sha256, sha256Hex, sha256Base64url, hkdfSha256, encryptAesGcm, decryptAesGcm, randomBytes, randomUUID, generateCodeVerifier, generateCodeChallenge, generatePkcePair, base64urlEncode, base64urlDecode for cross-platform cryptography
File system — readFile, writeFile, mkdir, stat, fileExists, readJSON, writeJSON, ensureDir, isDirEmpty, runCmd and more — lazy-loaded for Node.js environments
import { fileExists, matchUriTemplate, sha256Hex } from '@frontmcp/utils';
const params = matchUriTemplate('users/{id}/posts/{postId}', 'users/123/posts/456');
// { id: '123', postId: '456' }
const hash = sha256Hex('hello world');
const exists = await fileExists('/path/to/file');
@frontmcp/sdk — core framework@frontmcp/auth — uses crypto utilities for PKCE, encryptionApache-2.0 — see LICENSE.
FAQs
Shared utility functions for FrontMCP - string manipulation, URI handling, path utilities, and more
We found that @frontmcp/utils demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.