
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@streamable-finance/sdk-redux
Advanced tools
SDK Redux for streamlined front-end application development with StreamPay Protocol
SDK-Redux is an application framework for building front-end applications that interact with the StreamPay Protocol.
More specifically, SDK-Redux is a wrapper library around @streamable-finance/sdk-core which adds state management to StreamPay related queries and operations.
Under the hood, SDK-Redux leverages popular Redux libraries Redux Toolkit & RTK Query.
SDK-Redux is in early active development and can have breaking releases without warning and without consideration for semantic versioning.
Requirements:
A brand-new scaffolded Redux store configuration looks something like this:
import { configureStore, ThunkAction, Action } from '@reduxjs/toolkit';
export const store = configureStore({
reducer: {
},
});
export type AppDispatch = typeof store.dispatch;
export type RootState = ReturnType<typeof store.getState>;
export type AppThunk<ReturnType = void> = ThunkAction<
ReturnType,
RootState,
unknown,
Action<string>
>;
We need to plug in the StreamPay SDK-Redux parts.
Import the following function:
import {
allSubgraphSliceEndpoints,
createApiWithReactHooks,
initializeSfApiSlice,
initializeSfSubgraphSlice,
initializeSfTransactionSlice
} from "@streamable-finance/sdk-redux";
Create the Redux slices:
export const { sfApi } = initializeSfApiSlice(createApiWithReactHooks);
export const { sfTransactions } = initializeSfTransactionSlice();
export const sfSubgraph = initializeSfSubgraphSlice(createApiWithReactHooks).injectEndpoints(allSubgraphSliceEndpoints);
Plug in the slices to the Redux store:
export const store = configureStore({
reducer: {
"sfApi": sfApi.reducer,
"sfTransactions": sfTransactions.reducer,
"sfSubgraph": sfSubgraph.reducer
}
});
Add the middleware:
export const store = configureStore({
reducer: {
"sfApi": sfApi.reducer,
"sfTransactions": sfTransactions.reducer,
},
middleware: (getDefaultMiddleware) =>
getDefaultMiddleware().concat(sfApi.middleware).concat(sfSubgraph.middleware),
});
Somewhere in your code, give instructions to the superfluidContext to locate Framework and Signer:
import { setFrameworkForSdkRedux, setSignerForSdkRedux } from "@streamable-finance/sdk-redux";
setFrameworkForSdkRedux(chainId, sdkCoreFramework);
setSignerForSdkRedux(chainId, ethersWeb3Provider.getSigner());
That should be it! You should now be able to dispatch messages to StreamPay reducers & use the React hooks.
Read about RTK-Query queries here: https://redux-toolkit.js.org/rtk-query/usage/queries
Example using React Hook:
const {
data: pagedStreams,
isUninitialized,
isFetching,
isLoading,
isError,
error,
refetch,
} = sfSubgraph.useStreamsQuery({
chainId: queryChainId,
filter: {
token: superTokenAddress,
sender: senderAddress
},
pagination: {
skip: (page - 1) * pageSize,
take: pageSize
},
ordering: {
orderBy: "currentFlowRate",
orderDirection: "desc"
}
}, {
pollingInterval: 5000 // Not necessary to use but nice-to-have additional option by RTK-Query.
});
Read about RTK-Query queries here: https://redux-toolkit.js.org/rtk-query/usage/mutations
Example using React Hook:
const tx = await sfApi.createFlow({
senderAddress: signerAddress,
receiverAddress: receiver,
flowRateWei: flowRate,
chainId,
superTokenAddress: superToken,
waitForConfirmation,
}).unwrap();
All mutations trigger tracking for transaction progress (stored in transactionSlice) and transaction monitoring for re-orgs (all cached data is re-fetched in case of a re-org).
FAQs
SDK Redux for streamlined front-end application development with StreamPay Protocol
We found that @streamable-finance/sdk-redux demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.