
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@layers/onboarding-contracts
Advanced tools
Runtime-neutral contracts and collection policy for Layers one-paste onboarding
@layers/onboarding-contractsRuntime-neutral schemas, hashing rules, version constants, and the executable collection policy for the one-paste onboarding protocol.
The canonical authoring files remain under
packages/shared-types/src/http/onboard-agent. pnpm sync copies the exact
approved subset into this independently publishable package; pnpm sync:check
fails on any byte drift. Consumers must pin an exact package version and load
manifest.json before source inspection.
Every SHA-256 in the manifest covers the exact emitted file bytes. Consumers must verify those bytes before parsing rather than reserializing JSON locally. The exported collector target and private-output descriptors are inert data; this package does not spawn a process, open a pipe, or read a workspace. A host must verify the package, manifest, integrity record, and binary checksums before it permits the collector to inspect source.
The V1 policy deliberately permits no follow-up file reads. A later bounded second-pass implementation must publish a new collection-policy version rather than silently widening V1.
The package contains no service credentials, application runtime code, private
database schema, or source content. Generated Go policy input consumes the
exported collection-policy-v1.json; Go and npm consumers do not restate its
constants.
FAQs
Runtime-neutral contracts and collection policy for Layers one-paste onboarding
The npm package @layers/onboarding-contracts receives a total of 9 weekly downloads. As such, @layers/onboarding-contracts popularity was classified as not popular.
We found that @layers/onboarding-contracts demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.