
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@galaxy-stack/ai-coder-core
Advanced tools
Platform-neutral runtime for the Galaxy AI Coder single agent. Core exception under @galaxy-stack, versioned by the galaxy-blackhole organization. Consumed by galaxy-code (Blackhole CLI), galaxy-vscode-extension, and galaxy-desktop.
Provider-neutral, platform-neutral runtime for the Galaxy AI Coder single agent. The same core is intended for:
galaxy-code v2 — deterministic Node.js CLI laboratory;galaxy-vscode-extension — VS Code host adapters;galaxy-desktop — Tauri host adapters.The single-agent runtime, context manager, prompt assembler, tool registry, approval policy, checkpoint format, trace protocol, lexical retrieval, and completion gate are implemented and covered by deterministic tests.
galaxy-code v2 is the reference conformance host. VS Code and Desktop should
not copy runtime logic; they should implement the same ports and pass the same
host conformance fixtures first.
This package is still pre-integration: only galaxy-code passes the full
conformance gate today. Optional MCP, semantic retrieval, background terminal
sessions, and subagents are outside the current runtime baseline.
All releases before 1.0.0 are development quality. Every release carries an
explicit semver pre-release tag (x.y.z-alpha.N) while the host conformance
gate is still running; stable-looking x.y.z numbers are reserved for
post-1.0.0 releases. Publish pre-releases with a dist tag
(npm publish --tag alpha) so npm install @galaxy-stack/ai-coder-core@latest
never upgrades a consumer to an unverified alpha.
Every behavior- or API-level fix lands in CHANGELOG.d
as a dated fragment (date, time, area, before/after, regression requirement)
and is compiled into CHANGELOG.md at release time. When reading
any audit or live run, compare the recorded packageVersion against
CHANGELOG.md before concluding that a fixed defect recurred.
Publishing is automated through npm trusted publishing (OIDC, no stored npm
token): every push to main runs the conformance gate and
.github/workflows/publish.yml publishes the
package only when package.json carries a version that npm does not have yet.
Pre-release versions publish under the alpha dist tag, so
npm install @galaxy-stack/ai-coder-core@latest never jumps to an unverified
alpha.
AiCoderTaskContract. If command.run is active, the
host must supply the exact concrete non-interactive interpreter contract;
the runtime refuses missing/unknown shell metadata before a model request.beforeHash, delete has a null afterHash, and at least
one hash is non-null. Later validation has explicit workspace/path scope.satisfied; waived does not close
a required criterion.trusted_host provenance assertion).unknown unless the
host returns a structured result. Hosts must honor the supplied signal and
absolute deadline.noProgressPolicy
(advisory by default: escalating nudges at observationNudgeThresholds,
blocked only after the final threshold; strict preserves the older
first-incident accounting).request
-> capability + tool-policy snapshot
-> core-owned prompt snapshot + canonical user-task contract
-> bounded context assembly
-> one streamed model round
-> zero or more correlated tool calls
-> atomic batch preflight (IDs, budget, visible registry, canonical JSON)
-> sequential per-call schema/policy/approval/host adapter
-> bounded untrusted observation + trusted declared effects
-> repeat
-> evidence-ready tool-free finalization turn
-> final report candidate
-> model-actionable evidence gate
-> runtime-owned final-report persistence (when a store is configured)
-> completion-gate trace + durable trace flush (when trace is configured)
-> fresh workspace fingerprint
-> deterministic completion gate
-> completed
See ARCHITECTURE.md, PROMPT_CONTRACT.md, TOOL_EFFECT_PROFILE.md, and HOST_CONFORMANCE.md for integration contracts.
src/
├── approval/ # fail-closed approval policy
├── context/ # context budget, token ledger, checkpoints, output bounds
├── ports/ # host capability interfaces and PortResult
├── prompt/ # versioned system prompt assembly
├── retrieval/ # bounded provider-neutral lexical evidence
├── runtime/ # run controller, state machine, completion gate, trace emitter
└── tools/ # schemas, descriptors, registry and provider protocol
Requires Node.js 20 or newer.
npm install
npm run verify
Optional fast pre-push gate:
git config core.hooksPath .githooks
npm run verify runs strict TypeScript checks, all source tests, a clean build,
and a public dist smoke test. npm pack --dry-run should also be checked
before publishing or consuming the package from another repository.
npm test writes TEST_ERROR_LOG.md and per-run evidence under
.galaxy/tests/: timestamped assertion results, failure stacks, test counts,
commit and source fingerprint. The reporter is development-only and runs without
a galaxy-code checkout. Raw tsx --test invocations bypass this reporter.
The deterministic end-to-end host gate lives in galaxy-code:
cd ../../galaxy-code
npm run check
FAQs
Platform-neutral runtime for the Galaxy AI Coder single agent. Core exception under @galaxy-stack, versioned by the galaxy-blackhole organization. Consumed by galaxy-code (Blackhole CLI), galaxy-vscode-extension, and galaxy-desktop.
The npm package @galaxy-stack/ai-coder-core receives a total of 1,080 weekly downloads. As such, @galaxy-stack/ai-coder-core popularity was classified as popular.
We found that @galaxy-stack/ai-coder-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.