
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@sylphx/citra-darwin-arm64
Advanced tools
Optional pure-Rust MCP server binary for darwin-arm64. Installed as an optionalDependency of @sylphx/citra. Sole-Rust; fail-closed if missing.
Platform native binary for darwin-arm64 used by @sylphx/citra.
optionalDependency of @sylphx/citra when OS/CPU matchbin/citra-mcp-serverPrefer the umbrella package (recommended):
npm install -g @sylphx/citra
You normally do not need to install this package directly. npm selects the matching platform package.
This package is not a separate product surface. It is the native engine binary for one platform. There is no TypeScript PDF runtime and no engine “opt-in” flag for production.
FAQs
Optional pure-Rust MCP server binary for darwin-arm64. Installed as an optionalDependency of @sylphx/citra. Sole-Rust; fail-closed if missing.
We found that @sylphx/citra-darwin-arm64 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.