
Security News
Another Round of TEA Protocol Spam Floods npm, But It’s Not a Worm
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.
@oribuild/tsserver-lean
Advanced tools
Implements a tiny sub-set of tsserver, also using different internal APIs. Its reason d'etré is to i) emit diagnostics for a particular TypeScript module; ii) doing the least amount of work possible.
tsserver-lean expects communication to be done through its stdin and stdout pipes, like tsserver. It expects a set of requests defined in protocol.ts that are mapped to responses in a handler, on session.ts.
After a refactor, we are now using TypeScript's ProjectService API, that is responsible for managing multiple configured projects. With current setup, that means that we have a ProjectService for each project that we've requested diagnostics for. It has several efficiency affordances like caching of many adjacent functionality (ScriptInfo, module resolution, dependency type checkings) and the ability to extract diagnostics directly from a source file.
There are some contracts and premises that is worth being aware of:
tsserver-lean uses readline to read its input, so whenever we want to programmatically write to the process' stdin, it is required that a \n is added to the end of the request message.tsserver-lean will write a \n to its stdout, so it is required that the client reads until it finds a \n to know that the response has ended.So far, the only need for this server is to emit diagnostics for a particular module, on demand.
{ "command": "geterr", "type": "request", "seq": 0, "arguments": { "files": ["path/a/.ts", "path/b/.ts"] } }
Used as a first message sent to stdout to indicate a successful start-up.
{ "command": "handshake", "type": "request", "seq": 0 }
A new @oribuild/tsserver-lean version is published in two cases:
main, as a suffixed version i.e <version>-<commit-hash>package.json versionThe way that @oribuild/tsserver-lean and oribuild versions are kept in sync is through yarn's workspace resolution protocol.
Note that for 2., it is also necessary to manually update the oribuild's package version, so a new version of both are published to npm. Don't change the @oribuild/tsserver-lean version in oribuild's dependency dictionary. As an example, assuming that I'm manually bumping tsserver-lean from 0.0.1 to 0.0.2, and oribuild is in 0.0.5, here's a snippet of the changes that need to be made:
"name": "@oribuild/tsserver-lean",
--- "version": "0.0.1"
+++ "version": "0.0.2
"name": "oribuild",
--- "version": "0.0.5"
+++ "version": "0.0.51"
FAQs
lean subset of tsserver that only supports typechecking
The npm package @oribuild/tsserver-lean receives a total of 50 weekly downloads. As such, @oribuild/tsserver-lean popularity was classified as not popular.
We found that @oribuild/tsserver-lean demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.

Security News
PyPI adds Trusted Publishing support for GitLab Self-Managed as adoption reaches 25% of uploads

Research
/Security News
A malicious Chrome extension posing as an Ethereum wallet steals seed phrases by encoding them into Sui transactions, enabling full wallet takeover.