
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@layers/cli
Advanced tools
npm install -g @layers/cli fetches the layers binary for your platform (macOS, Linux, and Windows, x64 and arm64) and verifies its SHA256 against the release's checksums.txt before installing it.
Run layers setup in a repo to bind it to the Layers MCP, or layers --help for everything else.
CI publishes this package. The npm-publish job in
.github/workflows/release-cli.yaml runs on a cli/v* tag and authenticates to
npm with OIDC through npm trusted publishing. There is no npm token.
One-time setup on npmjs.com, required once per package before the first CI publish:
@layers/cli package page and go to Settings.layers, the repository to layers,
the workflow filename to release-cli.yaml, and the environment to
npm-publish.Until npm holds that record, the publish step fails with E404 or E403.
FAQs
Layers CLI: connect a repo to the Layers Growth MCP from the terminal.
The npm package @layers/cli receives a total of 234 weekly downloads. As such, @layers/cli popularity was classified as not popular.
We found that @layers/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.