
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@theneuralledger/research
Advanced tools
Evidence-first TNL research skills, orchestration, and application.
@theneuralledger/researchShared, evidence-first research contracts and orchestration for The Neural Ledger.
The package contains six immutable research skills, bounded TNL/Docdex/web/Codali adapters, tenant-scoped result caching, deterministic graders, an authorized HTTP service boundary, a standalone research workspace, and an MCP App resource.
npm run build --workspace @theneuralledger/research
TNL_RESEARCH_DEV_SERVICE=1 node packages/research/dist/service-bin.js
Open http://127.0.0.1:7425. The development entrypoint uses synthetic evidence,
accepts loopback-only development identity headers, and refuses to start when
NODE_ENV=production.
Production deployments import ResearchOrchestrator into the authenticated TNL
service and provide durable tenant storage plus configured TNL, Docdex, approved
web, and Codali HTTPS adapters. Credentials remain server-side. The research
runtime never shells out from browser code and never modifies BDYA state.
asOf times remain distinct.TNL Bot and is not trading advice.FAQs
Evidence-first TNL research skills, orchestration, and application.
We found that @theneuralledger/research demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.