
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@lenml/llmdx
Advanced tools
LLMDX = LLM + Markdown + Developer Experience/Execution
🚧 开发中 🚧
🚧WORK IN PROGRESS🚧
Not officially released yet. The following is a simple introduction generated and may not have some functions.
LLMDX: Scalable, Parameterized LLM Automation with Markdown
LLMDX is an advanced tool for deploying and managing LLM-powered services, all configured through Markdown. With LLMDX, users can define tasks across multiple Markdown endpoints and utilize dynamic parameters to customize each LLM task, creating interactive, scalable workflows.
A single command (llmdx -f task1.md task2.md ...) reads multiple Markdown configuration files, launches endpoints, and connects to your LLM provider of choice. LLMDX can prompt users to complete an initial form, adapting each task based on input parameters, making it easier than ever to deploy complex, customized LLM services.
Core Features:
LLMDX combines the power of Markdown, parameterized inputs, and flexible service deployment to simplify and enhance LLM workflows, making it an ideal solution for developers and teams looking to build intelligent, dynamic LLM services.
GPL-v3
FAQs
`LLMDX = LLM + Markdown + Developer Experience/Execution`
The npm package @lenml/llmdx receives a total of 8 weekly downloads. As such, @lenml/llmdx popularity was classified as not popular.
We found that @lenml/llmdx demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.