
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@syncrona/credential-store
Advanced tools
Shared encrypted credential store for SyncroNow AI (core CLI and MCP server).
Shared encrypted credential store for SyncroNow AI. It is the single source of
truth for at-rest credential storage used by both the syncrona CLI and
the @syncrona/mcp-server, so the encryption format, key derivation, file
naming, and on-disk layout never diverge between processes.
~/.syncrona/
config.json # { "activeInstance": "<instance>" }
credentials/<instance>.enc # AES-256-GCM "iv:authTag:ciphertext" (hex)
Async (used by the core CLI, read + write):
saveCredentials(instance, user, password)loadCredentials(instance) — throws if missinglistInstances()removeCredentials(instance) / removeAllCredentials()setActiveInstance(instance) / getActiveInstance()resolveCredentialsFromStore(instance?)getSyncronaDir()Sync (used by the MCP server during secrets resolution; never throw, return
null on any failure):
getActiveInstanceSync()loadCredentialsSync(instance)Low-level primitives are also exported: getStoreKey, getStoreKeySource,
getMachineKey, encrypt, decrypt, instanceToFilename,
filenameToInstance.
The encryption key is resolved by getStoreKey() with the precedence:
SYNCRONA_STORE_KEY — an explicit 32-byte key (64 hex chars or base64),
for CI / secrets managers. Strongest option.@napi-rs/keyring dependency is installed; opt out with
SYNCRONA_USE_KEYCHAIN=0 (e.g. a headless CI box with no keychain). A random
256-bit master key is kept in the OS keychain (macOS Keychain / Windows
Credential Manager / libsecret).@napi-rs/keyring is unavailable (or explicitly disabled).Reads fall back to the machine-derived key so pre-existing files keep
decrypting. getStoreKeySource() reports which path won ("env" /
"keychain" / "machine"). See the core README "Credential storage security"
section for hardening recommendations.
FAQs
Shared encrypted credential store for SyncroNow AI (core CLI and MCP server).
The npm package @syncrona/credential-store receives a total of 1 weekly downloads. As such, @syncrona/credential-store popularity was classified as not popular.
We found that @syncrona/credential-store demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.