
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@txn-dev/mcp-server
Advanced tools
MCP server for txn.dev - let any AI assistant manage agent payments.
Works with Claude Desktop, Cursor, Windsurf, and any MCP-compatible client.
Add to your MCP client config:
{
"mcpServers": {
"txn": {
"command": "npx",
"args": ["-y", "@txn-dev/mcp-server"],
"env": {
"TXN_API_KEY": "txn_live_..."
}
}
}
}
Get your API key at txn.dev/dashboard/api-keys.
| Tool | Description |
|---|---|
create_wallet | Create a new agent wallet |
list_wallets | List all wallets in your org |
pay | Transfer funds between wallets |
get_balance | Check a wallet's balance |
fund_wallet | Generate a Stripe checkout link to add funds |
Once connected, ask your AI assistant things like:
| Variable | Required | Description |
|---|---|---|
TXN_API_KEY | Yes | Your txn.dev API key |
MIT
FAQs
MCP server for txn.dev. Lets Claude, Cursor and Windsurf pay agents and hire humans.
The npm package @txn-dev/mcp-server receives a total of 45 weekly downloads. As such, @txn-dev/mcp-server popularity was classified as not popular.
We found that @txn-dev/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.