
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@standard-server/shared
Advanced tools
Internal types and utilities shared across the Standard Server ecosystem
@standard-server/shared contains internal types and utilities shared across the @standard-server ecosystem — small helpers for arrays, objects, JSON, iterators, promises, queues, IDs, URIs, and more.
It has no runtime dependencies and works in any JavaScript environment. The package exists so the other @standard-server packages can share these building blocks without duplication; its API follows their needs and is not designed for direct use in applications.
Standard Server ships as a small ecosystem of packages:
| Package | Description |
|---|---|
@standard-server/core | The shared contract: types, body parsing rules, validators, and SSE helpers |
@standard-server/fetch | Fetch API adapter for browsers, workers, and other Fetch-based runtimes |
@standard-server/node | Node.js HTTP and HTTP/2 adapter |
@standard-server/fastify | Fastify adapter built on the Node.js adapter |
@standard-server/aws-lambda | AWS Lambda adapter with response streaming |
@standard-server/peer | Message-based adapter for WebSocket, MessagePort, and custom transports |
@standard-server/shared | Internal utilities shared across the ecosystem |
For the project overview and the public contract of the ecosystem, see the core documentation.
Like what we build over at middleapi? You can help keep it going through GitHub Sponsors or Open Collective. Every bit helps! 🚀
The screenshot API for developers |
We're hiring NYC based engineers |
MisskeyHQDecentralized microblogging SNS born on Earth |
Guillermo Rauch |
LN Markets |
David Walsh | IPv4Addr | Robbe Vaes | Aidan Sunbury | soonoo | Kevin Porten | Denis |
Christopher Kapic | Tom Ballinger | Sam | Titoine | Igor Makowski | hanayashiki | Lev Dubinets |
Kelly Peilin Chan | Guy Ariely | PaulSenon | Alex | Andrey Gubanov |
With thanks to 36 past sponsors who helped get us here.
Distributed under the MIT License. See LICENCE for more information.
FAQs

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.