
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@t2000/id
Advanced tools
Agent ID — on-chain agent identity registry client for the t2000 stack (Sui). Build register/update/ownership/active transactions against the agent_id::registry Move package.
Agent ID — a tiny, dependency-light client for the on-chain agent_id::registry Move package (Sui mainnet). Build unsigned transactions that register and manage an agent's on-chain identity; the caller signs (the agent's keypair, or a sponsor co-signs gas for 0-SUI agents).
Part of the t2000 agent stack. See the developer docs at docs.t2000.ai.
npm install @t2000/id @mysten/sui
import { buildRegisterTx, AGENT_ID_REGISTRY_ID } from "@t2000/id";
// Register the SIGNER as an agent (self-sovereign: sender == agent).
const tx = buildRegisterTx({
mcpEndpoint: "https://my-agent.example/mcp",
paymentMethods: ["x402"],
});
// → sign with the agent keypair + execute (optionally sponsor the gas).
| Function | Move call | Signer |
|---|---|---|
buildRegisterTx(reg?) | register | the agent |
buildUpdateTx(reg?) | update (full-replace) | the agent |
buildSetActiveTx(agent, active) | set_active | the agent |
Two tiers of ids (S.1049):
MAINNET_AGENT_ID_PACKAGE_ID / MAINNET_AGENT_ID_REGISTRY_ID — literal
mainnet trust anchors, never influenced by the environment. Anything that
verifies a transaction before signing (allowlists, intent guards) must
use these.AGENT_ID_PACKAGE_ID / AGENT_ID_REGISTRY_ID — builder ids, overridable
via the same-named env vars for testnet/dev. These are conveniences for
constructing transactions, not a security boundary: a guard that read
them would let whoever controls the environment supply both the transaction
and the yardstick it is checked against.MIT
FAQs
Agent ID — on-chain agent identity registry client for the t2000 stack (Sui). Build register/update/ownership/active transactions against the agent_id::registry Move package.
The npm package @t2000/id receives a total of 3,021 weekly downloads. As such, @t2000/id popularity was classified as popular.
We found that @t2000/id demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.