
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@t2000/id
Advanced tools
Agent ID — on-chain agent identity registry client for the t2000 stack (Sui). Build register/update/ownership/active transactions against the agent_id::registry Move package.
Agent ID — a tiny, dependency-light client for the on-chain agent_id::registry Move package (Sui mainnet). Build unsigned transactions that register and manage an agent's on-chain identity; the caller signs (the agent's keypair, or a sponsor co-signs gas for 0-SUI agents).
Part of the t2000 agent stack. See the developer docs at docs.t2000.ai.
npm install @t2000/id @mysten/sui
import { buildRegisterTx, AGENT_ID_REGISTRY_ID } from "@t2000/id";
// Register the SIGNER as an agent (self-sovereign: sender == agent).
const tx = buildRegisterTx({
mcpEndpoint: "https://my-agent.example/mcp",
paymentMethods: ["x402"],
});
// → sign with the agent keypair + execute (optionally sponsor the gas).
| Function | Move call | Signer |
|---|---|---|
buildRegisterTx(reg?) | register | the agent |
buildUpdateTx(reg?) | update (full-replace) | the agent |
buildSetActiveTx(agent, active) | set_active | the agent |
Two tiers of ids (S.1049):
MAINNET_AGENT_ID_PACKAGE_ID / MAINNET_AGENT_ID_REGISTRY_ID — literal
mainnet trust anchors, never influenced by the environment. Anything that
verifies a transaction before signing (allowlists, intent guards) must
use these.AGENT_ID_PACKAGE_ID / AGENT_ID_REGISTRY_ID — builder ids, overridable
via the same-named env vars for testnet/dev. These are conveniences for
constructing transactions, not a security boundary: a guard that read
them would let whoever controls the environment supply both the transaction
and the yardstick it is checked against.MIT
FAQs
Agent ID — on-chain agent identity registry client for the t2000 stack (Sui). Build register/update/ownership/active transactions against the agent_id::registry Move package.
The npm package @t2000/id receives a total of 0 weekly downloads. As such, @t2000/id popularity was classified as not popular.
We found that @t2000/id demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.