
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@hypit/hypit
Advanced tools
1 command, 100 variants, 100M views.
Demo • Quickstart • Develop • 简体中文
⭐ Help more people find Hypit and grow the community. Star this repo!
Hypit gives AI agents (Claude Code, Codex...) a language and system to create video. Drop in a video, and your agent clones it as a complete workflow: footage, captions, B-roll and effects, all anchored to words instead of seconds.
To be clear: cloning a video is the fastest way in, not the only one. You can start from our templates, or just describe the video you want and your agent writes the workflow from scratch. Generation models are optional too: a workflow can compile captions, motion graphics and code-rendered visuals into a finished video without calling a generation model or incurring its service charges.

SVML source on the left, with the corresponding video rendered live on the right.
Install the Hypit CLI (Node.js 22.15 or newer):
npm install -g @hypit/hypit
Add the Skill to your coding agent:
npx skills add hypit-ai/hypit -g
This installs the Skill. On first use, your agent checks for the Hypit executable and helps prepare it if needed. Your video project can live anywhere.
Hypit is free to use; your Coding Agent and model services have their own accounts and charges. HypiHub is our recommended hosted model service. You can also use your own API or local models; tell your agent the service name and API documentation so it can set up the appropriate connection.
Agent environments and entry partners · Model and deployment services
Watch the complete video examples on GitHub.
The /hypit skill is available to coding agents. Start a session in any empty or existing project
directory and ask it to create videos for you:
/hypit Clone this video: /path/to/video.mp4, and replace the ranking content with a comparison of Hypit (official website: hypit.ai) with other AI video products.
Or start without a reference video:
/hypit Make a ranking video that puts Hypit in S tier.
Your agent can check the environment, request the credentials the video needs, generate the material, and build the finished composition.
Drop in a video and your agent clones the whole workflow — or describe what you want and it writes one from scratch. Either way you get an editable, re-runnable composition, not a one-off render.
Star us, and you will receive all release notifications from GitHub without any delay!

Pull requests are welcome, and documentation, examples and translations count as much as code. Pick up an open issue or open one for what you want to work on, and we will help you land it. CONTRIBUTING.md has the setup, the checks CI runs and the pull request flow.
Creating a component is ordinary video-production work, and the component normally stays with the video project that owns it. When its owner wants to share it, the same package can be handed off as a versioned tarball or published under the owner's npm scope or private registry. Proposals for a component maintained in Hypit's official Distribution begin with an issue describing the shared product need; official inclusion is separate from normal community sharing.
The Development Guide covers the prerequisites, the daily commands and the repository layout.
| Bug reports | Open an issue |
| Feature requests | Open an issue |
| Questions | Discord or Telegram |
Hypit is released under the Hypit Open Source License. The videos and other outputs you create belong to you; third-party models and services may have their own terms.
Partnership Community: LINUX DO
FAQs
Hypit video authoring Distribution for AI agents
The npm package @hypit/hypit receives a total of 5,893 weekly downloads. As such, @hypit/hypit popularity was classified as popular.
We found that @hypit/hypit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.