
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@polyxd/core
Advanced tools
The framework-free heart of Polyxd rendering: document types, JSON Pointer bindings, localised formatting, the renderer's decisions, and a headless surface model every renderer walks the same way
The framework-free heart of rendering a Polyxd UI document: the document types, JSON Pointer bindings, localised formatting, every decision the renderer makes instead of the model, and a headless surface model. No DOM, no framework, no dependencies. @polyxd/react and @polyxd/web are both built on it, and a renderer for another platform starts here.
import { createSurface } from "@polyxd/core";
const surface = createSurface(doc, {
data: { quote },
locale: "en-GB",
onAction: ({ name, context, source }) => handlers[name]?.(context),
onDataChange: (data) => save(data),
onDismiss: () => close(),
});
surface.byId.get(doc.root); // walk the tree from the root
surface.text({ path: "/quote/amount" }, { type: "currency", currency: "GBP" }); // "£40.00"
surface.setValue("/draft/amount", 40); // inputs write here; subscribers redraw
surface.dispatch(node.action, scope, node.id); // ui.dismiss → onDismiss; everything else → onAction
surface.subscribe((data) => render());
| Module | Exports |
|---|---|
| Document | UIDocument, Node, Action, ActionEvent, FrameLayout, NavigationPlacement, COMPONENTS, RENDERER_ACTIONS, indexById, mainNavigation |
| Bindings | get, set, resolve, resolveContext, resolveDeep, absolute, childPointer, asList, isBinding, itemScopes, ROOT_SCOPE |
| Formatting | formatValue, resolveFormat, safeColor, currencySymbol, formatCount, formatPercent |
| Surface | createSurface, a11yAttributes, dispatchAction, contextWithValue, copyText, rowChangeAction, isRendererAction |
| Choice | optionsOf, planChoice (chips, people or list; searchable past 10), optionKey, matchesQuery, partitionRecent, toggleSelection, isSelected, searchPlaceholder, idOf |
| State machines | stepsReducer, initialStep, isLastStep, stepsProgress, taskStatus, tasklistReducer, tasklistProgress; selectedView, viewsReducer; splitReducer, initialSplit, splitPanes, splitSelection, splitItemValue, clampShare |
| Layout rules | frameWidth, placementFor, appBarTitle, documentTitle (the Frame); TABLE_COMPACT_PX, stackedColumns, isNumericColumn, paging, rowValue, nextSort, columnCount (Table); fitActions, minShown, menuOrder (ActionBar); collectionLayout, orderedIndices, moveItem, calendarMonth (Collection); treeRows, treeKey, typeAheadTarget, visibleWindow (Tree); activeFilters (FilterPanel) |
| Loading | skeletonShape, SKELETON_SHAPES, PATTERN_SHAPE, skeletonStatus |
| Shortcuts | parseShortcut, shortcutMatches, unmodified, isApplePlatform |
| Small marks | metricChange, gaugeState, meterHint, starsLabel, ratingSaid, maskSecret, groupSummary, avatarTone, initialsOf, iconPath |
| Content | richText (tokens for **bold**, *italic*, `code`, [text](href)), qrEncode, chart geometry (niceMax, axisLabel, treemap, verticalScale, flowLayout, markerShape), applyMask, colour parsing (parseColor, formatColor), file limits (formatBytes, refuseFile, fileLimits) |
Every renderer that uses these makes the same decisions from the same document: a Choice with three short options is chips everywhere, a Table stacks below 720px everywhere, ui.dismiss closes everywhere. The conformance suite in @polyxd/verifier checks that it does.
npm test -w @polyxd/core runs the unit tests: pointer resolution, formatting per locale, the reducers, control selection, the layout rules, shortcuts, and the headless surface.
FAQs
The framework-free heart of Polyxd rendering: document types, JSON Pointer bindings, localised formatting, the renderer's decisions, and a headless surface model every renderer walks the same way
The npm package @polyxd/core receives a total of 42 weekly downloads. As such, @polyxd/core popularity was classified as not popular.
We found that @polyxd/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.