
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@jesscss/parser-shared
Advanced tools
@jesscss/parser-sharedPublished runtime support for the Parseman grammar facts that the CSS, Less, SCSS, and Jess parsers compose. The CSS grammar keeps these modules external so downstream dialect packages can follow their composed pieces across the package boundary; parser consumers receive this package through the parser dependency closure.
The package intentionally has no root entrypoint. Its public surface is limited
to the three grammar-fact modules in exports.
Modules here are consumed by two or more parsers and are parser-specific. Anything used by one parser belongs in that parser. Anything general-purpose belongs elsewhere.
This package builds first. All four parsers depend on it, and building them
against a stale lib/ fails silently and green.
FAQs

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.