
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@glbforge/mcp
Advanced tools
GLBForge MCP server — 8 tools that let AI agents take 3D assets from generation to web-ready.
MCP server exposing the glbforge
pipeline to AI agents (Claude Code, Cursor, ...): analyze_glb,
optimize_glb, extrude_image, export_stl, list_profiles,
meshy_create_task, meshy_task_status, meshy_download.
claude mcp add glbforge -- npx -y @glbforge/mcp
Tool descriptions teach the routing that matters: flat artwork → deterministic extrusion (free, instant, exact); photographic/dimensional subjects → Meshy generation; everything → budget-checked optimization.
FAQs
GLBForge MCP server — 8 tools that let AI agents take 3D assets from generation to web-ready.
The npm package @glbforge/mcp receives a total of 167 weekly downloads. As such, @glbforge/mcp popularity was classified as not popular.
We found that @glbforge/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.