
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@stll/docx-utils
Advanced tools
Low-level helpers for reading and writing DOCX/OOXML zip packages: text and binary extraction, relationship and content-type management, and namespace constants.
Low-level helpers for reading and writing DOCX/OOXML zip packages.
The package wraps the mechanical parts of working with a DOCX file: loading and repacking the underlying zip, extracting text or binary parts, managing relationships and content types, and the OOXML namespace constants those operations need.
import { loadDocx, extractText, ensureRelationship } from "@stll/docx-utils";
const zip = await loadDocx(bytes);
const text = await extractText(zip, "word/document.xml");
bun add @stll/docx-utils
OOXML_NS / OoxmlPrefix — OOXML namespace constants and prefixes.loadDocx, repackZip, extractText, extractBinary, DOCX_COMPRESSION —
zip-level read and write helpers.findNextRId, ensureContentType, ensureRelationship — relationship and
content-type management.Apache-2.0
FAQs
Low-level helpers for reading and writing DOCX/OOXML zip packages: text and binary extraction, relationship and content-type management, and namespace constants.
The npm package @stll/docx-utils receives a total of 8,549 weekly downloads. As such, @stll/docx-utils popularity was classified as popular.
We found that @stll/docx-utils demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.