
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@mupag/widget
Advanced tools
Browser SDK para abrir o checkout MuPag em modal via iframe, sem redirect obrigatório.
@mupag/widget@0.1.1 está publicado no npm e pode ser usado pelo npm, unpkg ou jsDelivr. O
domínio CDN próprio da MuPag ainda está pendente e não é anunciado como disponível.
npm install @mupag/widget
Alternativa via unpkg:
<script src="https://unpkg.com/@mupag/widget@0.1.1/dist/widget.global.js" defer></script>
Alternativa via jsDelivr:
<script src="https://cdn.jsdelivr.net/npm/@mupag/widget@0.1.1/dist/widget.global.js" defer></script>
O bundle expõe apenas window.MuPagWidget com { MuPag, init, version }.
<button
data-mupag-widget
data-environment="test"
data-publishable-key="pk_test_..."
data-item-name="Plano Pro"
data-unit-amount-cents="10990"
data-quantity="1"
data-success-url="https://sua-loja.example/pagamento/sucesso"
data-cancel-url="https://sua-loja.example/carrinho"
>
Comprar agora
</button>
npm install @mupag/widget
import { MuPag } from "@mupag/widget";
const mupag = new MuPag({
environment: "test",
publishableKey: "pk_test_...",
});
await mupag.openCheckout({
items: [{ name: "Plano Pro", quantity: 1, unit_amount_cents: 10_990 }],
success_url: "https://sua-loja.example/pagamento/sucesso",
cancel_url: "https://sua-loja.example/carrinho",
customer_data: { email: "user@example.com" },
onSuccess: (charge) => console.log("Paid", charge),
onClose: () => console.log("Closed"),
});
publishable precisa do escopo checkout_sessions.create.environment é obrigatório e a chave deve corresponder a test (pk_test_) ou prd (pk_prd_).Idempotency-Key criptograficamente segura para cada nova sessão; informe
idempotencyKey para reutilizar a mesma operação em uma tentativa controlada.eval, top-level await ou dependências runtime externas.postMessage aceita eventos apenas da origem e da janela do iframe ativo./c/{session_id}.checkoutBaseUrl explicitamente com a origem HTTPS.FAQs
Browser widget SDK for embedding MuPag checkout in merchant sites.
We found that @mupag/widget demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.