
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@pressa/cli
Advanced tools
Command-line interface for Pressa - Compile-as-a-Service. LaTeX in, PDF out.
npm install -g @pressa/cli
# Set your API key
pressa auth
# Compile a LaTeX file
pressa compile report.tex
# Compile with a specific engine
pressa compile report.tex --compiler xelatex
# Read from stdin
cat report.tex | pressa compile -
# JSON output (for AI agents)
pressa compile report.tex --json
pressa authConfigure your API key.
# Interactive
pressa auth
# Non-interactive
pressa auth --key pressa_xxxx
pressa compile <file>Compile a LaTeX file to PDF.
| Option | Description |
|---|---|
-c, --compiler | LaTeX compiler: pdflatex (default), xelatex, lualatex |
-o, --output | Output PDF filename |
--json | Machine-readable JSON output |
--no-download | Don't download PDF, just return URL |
-u, --url | API base URL override |
Use - as filename to read from stdin.
pressa usageShow your API usage statistics.
Plan: free
Used: 3/100 this month
Resets: April 30, 2026
API Key: pressa_c... (Test Key)
Config is stored in ~/.pressa/config.json:
{
"api_key": "pressa_xxxx",
"api_url": "https://api.pressa.dev"
}
cd cli
npm install
npm run build
npm run dev # watch mode
MIT
FAQs
CLI for Pressa - Compile-as-a-Service. LaTeX in, PDF out.
The npm package @pressa/cli receives a total of 15 weekly downloads. As such, @pressa/cli popularity was classified as not popular.
We found that @pressa/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.