
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@theneuralledger/cli
Advanced tools
Command-line access and an append-only foreground intelligence daemon for The Neural Ledger.
export TNL_API_KEY=tnl_...
npx -y @theneuralledger/cli latest
npx -y @theneuralledger/cli search "semiconductor export restrictions"
npx -y @theneuralledger/cli asset NVDA
npx -y @theneuralledger/cli daemon --interval 60
Commands: latest, search, asset, status, watch, daemon, mcp, and serve.
The daemon remains in the foreground so a process supervisor can manage it. It stores immutable JSONL revisions and atomic cursor state under ~/.tnl-intelligence by default; set TNL_STATE_DIR or pass --state-dir to change the location. Cache, state, and lock files are private to the current user where the operating system supports POSIX permissions.
API keys are read only from TNL_API_KEY. There is deliberately no command-line API-key option because process arguments are commonly visible to other local users and monitoring systems.
FAQs
CLI and foreground intelligence daemon for The Neural Ledger.
The npm package @theneuralledger/cli receives a total of 8 weekly downloads. As such, @theneuralledger/cli popularity was classified as not popular.
We found that @theneuralledger/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.