
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@jesscss/style-resolver
Advanced tools
**Stylesheet import resolution across CSS, Less, SCSS, and Jess — include paths, load paths, and extension/index resolution.**
Stylesheet import resolution across CSS, Less, SCSS, and Jess — include paths, load paths, and extension/index resolution.
@jesscss/style-resolver is a building block for
Jess. Given a stylesheet's source and an import statement, it
figures out which file that import actually points to, applying each language's
lookup rules (Less and SCSS candidate expansion, partials, index files, search
paths).
It handles the mechanics of finding imports — extracting import statements from source, expanding a bare import path into the ordered list of candidate files a given language would try, and resolving that against a filesystem-like interface.
Import resolution is a shared concern the compiler and tooling both need. It is
also one of the building blocks toward the broader module/scoping story on the
Jess roadmap (whose headline is the post-.jess minimal browser build) — but this
package is just the resolver, not that feature.
This is an internal package. Most people should install
jess and use the jess CLI.
The JavaScript/TypeScript API is not yet stabilized and is intentionally
undocumented for now.
Alpha. Published to npm under both the latest and alpha dist-tags. Please
report bugs.
FAQs
Unknown package
The npm package @jesscss/style-resolver receives a total of 718 weekly downloads. As such, @jesscss/style-resolver popularity was classified as not popular.
We found that @jesscss/style-resolver demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.