
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@smbcloud/sigit
Advanced tools
A local coding agent powered by Onde Inference.
Runs on your machine. No API keys. No cloud round-trips.
npm install -g @smbcloud/sigit
npm pulls in the right binary for your platform automatically.
Supported targets:
| Method | Command |
|---|---|
| Homebrew | brew tap getsigit/tap && brew install sigit |
| pip | pip install sigit-code |
| uv | uvx --from sigit-code sigit |
| Cargo | cargo install sigit |
sigit
That starts the local terminal UI.
Add this to ~/.config/zed/settings.json:
{
"agent_servers": {
"siGit Code": {
"type": "custom",
"command": "sigit"
}
}
}
Then select siGit Code in the Zed assistant panel.
Install ACP Client, then add:
{
"acp.agents": {
"siGit Code": {
"command": "sigit",
"args": [],
"env": {}
}
}
}
| Platform | Architecture | Package |
|---|---|---|
| macOS | Apple Silicon (arm64) | @smbcloud/sigit-darwin-arm64 |
| macOS | Intel (x64) | @smbcloud/sigit-darwin-x64 |
| Linux | x64 | @smbcloud/sigit-linux-x64 |
| Linux | arm64 | @smbcloud/sigit-linux-arm64 |
| Windows | x64 | @smbcloud/sigit-windows-x64 |
| Windows | arm64 | @smbcloud/sigit-windows-arm64 |
© 2026 smbCloud (Splitfire AB).
FAQs
AI coding agent powered by local LLM via Onde Inference.
The npm package @smbcloud/sigit receives a total of 242 weekly downloads. As such, @smbcloud/sigit popularity was classified as not popular.
We found that @smbcloud/sigit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.