
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@true402.dev/rugcheck
Advanced tools
Terminal rug/honeypot check for any Base token — `npx @true402.dev/rugcheck 0x…` — pay-per-call over x402 (USDC, no account, no API key).
Stable · production-ready — semver-stable public API (v1.0).
On-chain rug / honeypot check for any Base token, from your terminal — one command, no install:
npx @true402.dev/rugcheck 0x4ed4E862860beD51a9570b96d89aF5E1B0Efefed
It tries true402's free trial first (a few free checks/day — no wallet needed). For unlimited checks, point it at a payer wallet and it pays true402's token-report over x402 (~$0.01 USDC on Base, no account, no API key — the wallet is the identity):
Works on Base (default), Ethereum and BNB Smart Chain — add --chain ethereum or --chain bsc.
Add --history to also show what has already happened to the token's liquidity — every removal
true402 has observed, and the other tokens drained in the same transaction. A honeypot simulation
answers "can I sell this right now"; it is blind to a pool that was drained last month and re-seeded.
Base only, since that is the chain the archive covers.
PAYER_PRIVATE_KEY=0x… npx @true402.dev/rugcheck 0x<token>
true402 rugcheck · 0x4ed4…Efed
🛑 AVOID (score 0/100)
• no tradeable WETH/USDC liquidity — effectively untradeable
checked on-chain: honeypot sim + liquidity + ownership · true402.dev
PAYER_PRIVATE_KEY is a Base wallet holding a little USDC (gas is sponsored by the facilitator).The verdict is a composite of an on-chain buy/sell honeypot simulation, liquidity depth, and contract structure (mint, ownership, kill switches). Powered by true402 — the machine-native x402 marketplace on Base.
Not in a terminal? Send any Base token address to @True402bot on Telegram, or use the browser check at https://true402.dev/check — same on-chain simulation, free, no wallet.
MCP (Claude Code / Desktop, Cursor, Hermes) · Hermes Agent · OpenClaw · ElizaOS · LangChain · CrewAI · Vercel AI SDK · Coinbase AgentKit · Virtuals GAME · CLI — same on-chain checks, one install command each: true402.dev/integrations
FAQs
Terminal rug/honeypot check for any Base token — `npx @true402.dev/rugcheck 0x…` — pay-per-call over x402 (USDC, no account, no API key).
The npm package @true402.dev/rugcheck receives a total of 33 weekly downloads. As such, @true402.dev/rugcheck popularity was classified as not popular.
We found that @true402.dev/rugcheck demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.