
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@glbforge/core
Advanced tools
Analyze, optimize, extrude, and export AI-generated 3D assets for the web — budgets, lint rules, KTX2, LODs, STL.
The engine behind glbforge: pure TypeScript analysis, optimization, extrusion, and export for glTF/GLB assets.
analyze(doc, {profile}) — geometry/texture/material stats, welded-space
topology (boundary, non-manifold, truly-redundant vertices), named lint
rules with fixes, budget scoringoptimize(doc, {profile, textureFormat}) — dedup → palette/join → weld →
meshopt-simplify (error ladder) → smooth normals → WebP or KTX2 → meshoptextrudeImage(bytes, opts) — raster/SVG silhouette → beveled watertight
mesh with the source image projected as texturetoStl(doc, {targetSizeMm}) — binary STL, world transforms baked, z-upmobile-hero, desktop-hero, product-configuratorFAQs
Analyze, optimize, extrude, and export AI-generated 3D assets for the web — budgets, lint rules, KTX2, LODs, STL.
The npm package @glbforge/core receives a total of 134 weekly downloads. As such, @glbforge/core popularity was classified as not popular.
We found that @glbforge/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.