
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@opentui/core
Advanced tools
OpenTUI is a TypeScript library on a native Zig core for building terminal user interfaces (TUIs)
OpenTUI is a library to build terminal user interfaces.
OpenCode uses OpenTUI in production for millions of users.
Website | Documentation | Packages
@opentui/core supplies the renderer and TypeScript API. You use imperative renderables and events directly. The
TypeScript packages call native Zig through an internal foreign function interface (FFI) boundary.
import { TextRenderable, createCliRenderer } from "@opentui/core"
const renderer = await createCliRenderer({ exitOnCtrlC: true })
renderer.root.add(new TextRenderable(renderer, { content: "Hello, OpenTUI!" }))
exitOnCtrlC: true calls renderer.destroy() when the user presses Ctrl+C. The code that creates the renderer must
call renderer.destroy() on every other shutdown path.
Install the package:
bun add @opentui/core
Then build your first app with the quickstart.
@opentui/core runs on Bun 1.3.0 or later, or on Node.js 26.4.0 or later with ECMAScript modules (ESM) and
--experimental-ffi.
The native ABI and the generated platform packages, such as @opentui/core-linux-x64, are internal distribution
surfaces, not application APIs.
Install the OpenTUI documentation as a skill for your AI coding assistant with npx skills:
npx skills add anomalyco/opentui --skill opentui
Add -g to install the skill globally.
OpenTUI is licensed under the MIT License.
FAQs
OpenTUI is a TypeScript library on a native Zig core for building terminal user interfaces (TUIs)
The npm package @opentui/core receives a total of 486,091 weekly downloads. As such, @opentui/core popularity was classified as popular.
We found that @opentui/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.