
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@sandbaseai/cli
Advanced tools
Node.js 20+ CLI for securely connecting Codex, Claude Code, Cursor, or Hermes to SandBase MCP.
npx -y @sandbaseai/cli connect --client codex
sandbase doctor --client codex
sandbase unregister --client codex
The CLI opens the SandBase authorization page. Secrets are never included in command-line arguments or browser URLs. SANDBASE_API_URL may override the API origin for development and tests.
FAQs
Secure SandBase MCP onboarding CLI
The npm package @sandbaseai/cli receives a total of 63 weekly downloads. As such, @sandbaseai/cli popularity was classified as not popular.
We found that @sandbaseai/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.