
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@tasklite/mcp
Advanced tools
TaskLite MCP server — build a full backend (projects, boards, data, REST endpoints) and a ready-made admin from Claude Code and other MCP clients
TaskLite MCP server — build a full backend (projects, boards, typed columns, data, REST endpoints with API keys) from Claude Code, and hand your client a ready-made admin.
New to TaskLite? No account needed first:
claude mcp add tasklite -- npx -y @tasklite/mcp
Then just tell Claude what you want to build — the sign_up tool creates your account, organization, and connection from the conversation (a strong random password is generated locally and never shown; use "forgot password" with your email for web access).
Already have an account? Create a key at TaskLite → Integrations → "Connect Claude Code" and use:
claude mcp add tasklite -e TASKLITE_API_KEY=tl_xxx -- npx -y @tasklite/mcp
Optional env: TASKLITE_API_URL (default https://api.tasklite.net), TASKLITE_APP_URL (default https://app.tasklite.net).
create_project → create_board → create_column × N — the schema.create_item / query_items — seed and inspect data.create_app → create_app_endpoint (with exposedColumns + RLS) → create_app_api_key — the REST surface for your frontend.get_app_spec / get_frontend_prompt — generate the frontend against it.adminUrl — the ready-made admin for the end client.tl_ key is exchanged for a short-lived JWT (POST /public/v1/auth/session); all calls run with the key owner's own permissions, never super-admin.npm install
npm run build
TASKLITE_API_KEY=tl_xxx TASKLITE_API_URL=http://localhost:3333 node dist/index.js
FAQs
TaskLite MCP server: build a full backend (projects, boards, data, REST endpoints), deploy a frontend onto it, and get a ready-made admin, from Claude Code and other MCP clients
The npm package @tasklite/mcp receives a total of 47 weekly downloads. As such, @tasklite/mcp popularity was classified as not popular.
We found that @tasklite/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.