
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@openrng/core
Advanced tools
VEO-2 types, schema, and shared primitives for the OpenRNG ecosystem.
VEO = Verifiable Execution Object — a standard format for recording, proving, and explaining AI decisions.
npm install @openrng/core
import { createVEO, validateVEO, createVEOHash } from '@openrng/core';
// Create a VEO for an AI execution
const veo = createVEO({
provider_id: 'my-service',
execution: {
prompt_hash: 'sha256-of-prompt',
output_hash: 'sha256-of-output',
model_id: 'gpt-4o',
latency_ms: 412,
cost: { total_tokens: 1500, cost_usd: 0.003 },
},
confidence: { score: 850, grade: 'AA' },
});
// Validate
const { valid, errors } = validateVEO(veo);
// Hash (for anchoring)
const hash = createVEOHash(veo);
| Class | Name | Use Case |
|---|---|---|
| VEO-2A | Raw Execution | Single AI call (chat, completion, inference) |
| VEO-2B | Composite Execution | Multi-step chains, agent pipelines |
| VEO-2C | Anchored Execution | With blockchain proof / Merkle anchor |
| VEO-2D | Governed Execution | With policy assertions, human approvals |
created → signed → anchored → indexed → verified
| Package | Purpose |
|---|---|
@openrng/core | Types, schema, validation (this package) |
@openrng/verify | Verify any VEO object |
@openrng/auto | Auto-instrument AI SDK calls |
MIT — OpenRNG
FAQs
VEO-2 types, schema, and shared primitives for OpenRNG
The npm package @openrng/core receives a total of 8 weekly downloads. As such, @openrng/core popularity was classified as not popular.
We found that @openrng/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.