
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
@hubspot/cli
Advanced tools
A CLI for HubSpot developers to enable local development and automation. Learn more about building on HubSpot.
For more information on using these tools, see Local Development Tooling: Getting Started
npm install -g @hubspot/cli
Once the @hubspot/cli has been added to a project, a config file named hubspot.config.yml will also be needed. It is recommended that the config file is kept in your $HOME directory.
cd ~
hs init
You can set up command autocompletion by running
hs completion
and copying the output to either your .bashrc or .zshrc, and then sourcing that file source ~/.bashrc source ~/.zshrc or restarting your terminal.
A full breakdown of the commands can be found on the local development tools reference page.
Note: When @hubspot/cli is installed local to a project, the commands need to be prefixed with either yarn if using yarn or npx if using npm.
There are two ways that the tools can authenticate with HubSpot.
hs init or hs auth personalaccesskey and follow the instructionshs auth oauth2OAuth2 and follow the stepsNote: The Account ID used should be the Test Account ID (not the developer app ID). Client ID and Client Secret are from the developer app.
The CLI will exit with one of the following exit codes:
0: A successful run1: There was a config problem or an internal error2: There are warnings or validation issuesThe best way to stay up to date is to check out the Github Releases and also follow our developer changelog posts for an easier to read breakdown of major changes.
FAQs
The official CLI for developing on HubSpot
The npm package @hubspot/cli receives a total of 37,918 weekly downloads. As such, @hubspot/cli popularity was classified as popular.
We found that @hubspot/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 40 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.