
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@loyaltyvip/cli
Advanced tools
Command-line interface for LoyaltyVIP — search the casino directory and access your loyalty data from the terminal.
Command-line interface for LoyaltyVIP. Output is JSON, ready to pipe to jq.
npm i -g @loyaltyvip/cli # or: npx @loyaltyvip/cli <command>
loyaltyvip casinos --state NV --rewards --limit 5
loyaltyvip casino bellagio-nv-880e8400
loyaltyvip programs "caesars"
LOYALTYVIP_API_KEY=lvip_live_... loyaltyvip tiers
LOYALTYVIP_API_KEY=lvip_live_... loyaltyvip player tax_year_summary --params '{"tax_year":2025}'
Commands: casinos, casino <slug>, programs (public); me, tiers, trips, offers, player <action> (need an API key via --key or LOYALTYVIP_API_KEY).
Get a key at https://loyaltyvip.com/dashboard/developer. MIT © movaMedia.
FAQs
Command-line interface for LoyaltyVIP — search the casino directory and access your loyalty data from the terminal.
We found that @loyaltyvip/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.