
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@polyxd/ds-editorial
Advanced tools
Editorial template pack for Polyxd (DTCG 2025.10 tokens): an original design to start from and make your own
Editorial — an original Polyxd template pack. Serif display, warm paper, hairline rules, a generous measure; magazines, publishing, long reads.
Fraunces for everything that is read, a plain grotesque for the small caps that label things, and warm paper under it all. Rules are hairlines, radii are nearly square, the measure runs to 72 characters, and the accent is oxblood rather than a UI blue. Cards have no shadow; only overlays lift. Dark mode is night paper with cream text and the same palette softened. For magazines, publishing tools, reading apps and anything that wants to feel set rather than built.
This is a template: not a reproduction of any design system, and meant to be changed. Start from it, keep what you like, and it stays a valid pack as long as polyxd check passes.
npx polyxd check packages/ds-editorial/manifest.json # every contract token, every contrast pair, both modes
Two ways in.
Edit these tokens. Every colour role in tokens/system.light.json and tokens/system.dark.json points at a named entry in that file's palette; change a palette entry and every role using it follows, or point a role at another entry to change one thing. Type, spacing, radii and motion are in tokens/system.json. tokens/semantic.json only aliases those and rarely needs touching. Run polyxd check after each change: it names any pair that no longer meets its contrast floor.
Or start from your own tokens. npx polyxd pack ./your-tokens.css --name yours drafts a pack from a stylesheet or a DTCG file and writes a mapping you correct; this template is then a reference for what each role is for.
Either way, rename it: name in manifest.json is the theme a surface asks for, and [data-pxd-theme="<name>"] is the selector the compiled CSS uses.
| Role | Family | Full stack |
|---|---|---|
display | Fraunces | Fraunces, Georgia, 'Times New Roman', Times, serif |
body | Fraunces | Fraunces, Georgia, 'Times New Roman', Times, serif |
label | Helvetica Neue | 'Helvetica Neue', Helvetica, Arial, sans-serif |
mono | ui-monospace | ui-monospace, SFMono-Regular, Menlo, Consolas, 'Liberation Mono', monospace |
Web fonts: Fraunces — from Google Fonts under the SIL Open Font License, not shipped with the pack. Add them to your page's <link>; without them the pack falls back to the stack after each name and still passes every check.
oxblood, is used for links, focus and danger; the four status colours are slate, moss, ochre and oxblood, all low-chroma so a notice sits in the page rather than on it.| File | What it holds |
|---|---|
manifest.json | Name, modes, default mode and provenance |
tokens/system.json | Primitives both modes share: fonts, sizes, spacing, radii, borders, motion |
tokens/system.light.json, tokens/system.dark.json | The palette and the editorial.sys.* roles for each mode, plus shadows |
tokens/semantic.json | The Polyxd contract, aliasing editorial.* |
Licence Apache-2.0, like the rest of Polyxd. Provenance in the manifest: original template by Polyxd.
logo.svg is Polyxd's own mark for this template, not anyone's logo: a small card drawn only from the template's tokens in its default mode (the ground, strong border and radius, the text and muted text, the primary action and one accent). packages/ds-kit/scripts/pack-logos.ts draws it, so it follows the tokens: change them and run node packages/ds-kit/scripts/pack-logos.ts to redraw it. A test fails if it goes stale.
FAQs
Editorial template pack for Polyxd (DTCG 2025.10 tokens): an original design to start from and make your own
The npm package @polyxd/ds-editorial receives a total of 20 weekly downloads. As such, @polyxd/ds-editorial popularity was classified as not popular.
We found that @polyxd/ds-editorial demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.