
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@modwrench/thunderstore
Advanced tools
ModWrench — Thunderstore MCP server. Discover and inspect mods on Thunderstore (Lethal Company, Valheim, R.E.P.O., Risk of Rain 2, Dyson Sphere Program, BONEWORKS, and other Unity co-op games) directly from any MCP-compatible AI client.
ModWrench's Thunderstore platform package. Read-only MCP tools for discovering and inspecting mods on Thunderstore — the dominant platform for Unity co-op games (Lethal Company, Valheim, R.E.P.O., Risk of Rain 2, Dyson Sphere Program, BONEWORKS, and many others).
Closes the v2 workbench loop: mw_read_load_order parses r2modman profiles locally; Thunderstore's tools enrich each installed mod with author, version, downloads, and current page URL.
thunderstore_list_communities — every community (game) on Thunderstorethunderstore_get_community — single community detailsthunderstore_list_mods — mods within a community (paginated summary)thunderstore_get_mod — single mod's metadata (latest version, total downloads, community listings)thunderstore_search_mods — substring search within a communitythunderstore_mod_versions — full version history of a specific modthunderstore_top_mods — highest-rated mods in a community, by Thunderstore's own ratingthunderstore_mod_dependencies — a mod's declared dependenciesthunderstore_resolve_dependencies — walk a mod's full dependency treeRead-only public API — no credentials required, no environment variables needed. Every tool here works anonymously.
Standalone:
npx @modwrench/thunderstore
Or composed into the meta-server via @modwrench/cli. See the project README for full setup.
FAQs
ModWrench — Thunderstore MCP server. Discover and inspect mods on Thunderstore (Lethal Company, Valheim, R.E.P.O., Risk of Rain 2, Dyson Sphere Program, BONEWORKS, and other Unity co-op games) directly from any MCP-compatible AI client.
The npm package @modwrench/thunderstore receives a total of 41 weekly downloads. As such, @modwrench/thunderstore popularity was classified as not popular.
We found that @modwrench/thunderstore demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.