
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@tsrx/core
Advanced tools
TypeScript Render Extensions (TSRX) — the shared parser and compiler infrastructure that powers TypeScript UI frameworks.
@tsrx/core is framework-agnostic. It provides the parser, AST definitions, scope
analysis, and code-generation utilities needed to target any framework runtime
using Ripple's syntax. Framework-specific packages (such as
@tsrx/ripple) build on top of @tsrx/core to produce the
runtime output for Ripple.
TSRX is an extension to TypeScript's syntax — in the same spirit that JSX is an extension to JavaScript. It adds a small set of orthogonal syntactic forms that are ergonomic for describing reactive UI, and leaves the semantics of those forms to the consuming framework.
A .tsrx file is a TypeScript module with TSRX enabled.
pnpm add @tsrx/core
import { analyzeTsrx, parseModule } from '@tsrx/core';
const ast = parseModule(source, 'App.tsrx');
const analysis = analyzeTsrx(ast, 'App.tsrx');
The parser produces an ESTree-compatible AST, augmented with the TSRX node types listed below. Framework compilers walk this AST to emit their own output.
The TSRX website is the canonical source for language documentation:
Keeping the language reference on the website avoids duplicating the specification here and keeps package docs focused on the core parser API.
@tsrx/core providesparseModule(source, filename, options?) — parse a TSRX module into an
ESTree AST.analyzeTsrx(ast, filename, options?) — run target-neutral semantic
validation before framework analysis or transformation. Pass collect: true,
typeOnly: true, or to_ts: true to collect non-fatal diagnostics for
editor/type-only output.createScopes, Scope, ScopeRoot, binding tracking
(import, prop, let, const, function, for_pattern, …).parseStyle, analyzeCss, renderStylesheets.isVoidElement, isBooleanAttribute, isDomProperty,
validateNesting.convertSourceMapToMappings.See src/index.js for the full exported surface.
@tsrx/core does not emit runtime code. Code generation lives in framework
packages (e.g. @tsrx/ripple).@tsrx/core does not ship a runtime. There is no reactivity, rendering, or
DOM code here.@tsrx/core does not lock consumers to a specific output format. Multiple
compile targets can share the same parser and analysis.MIT © Dominic Gannaway
FAQs
Core compiler infrastructure for TSRX syntax
The npm package @tsrx/core receives a total of 25,562 weekly downloads. As such, @tsrx/core popularity was classified as popular.
We found that @tsrx/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.