
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@sylphx/spine
Advanced tools
Spine is now repomap. This package is a thin alias of @sylphx/repomap (same MCP server and CLI).
Spine is now repomap — a map of your codebase for AI agents: code graph, hybrid search, call paths and change impact, with an interactive graph UI.
This package is a thin alias that installs @sylphx/repomap and runs it, so existing configs keep working. New installs should use:
npx -y @sylphx/repomap setup
Old tool names (architecture_*, codebase_search) are still accepted by the server.
FAQs
Spine is now repomap. This package is a thin alias of @sylphx/repomap (same MCP server and CLI).
The npm package @sylphx/spine receives a total of 808 weekly downloads. As such, @sylphx/spine popularity was classified as not popular.
We found that @sylphx/spine demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.