
Security News
OpenClaw Skill Marketplace Emerges as Active Malware Vector
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.
@webda/tsc-esm
Advanced tools
This module is part of Webda Application Framework that allows you to quickly develop applications with all modern prerequisites: Security, Extensibility, GraphQL, REST, CloudNative https://webda.io
This is a wrapper around tsc to compile typescript to esm format without the culprit of having to add '.js' at the end of your import.
When you work with typescript this is valid
import { MyClass } from './myclass';
But the official compiler will generate a file named myclass.js and you will have to write
import { MyClass } from './myclass.js';
This is not really clean in my opinion, so this wrapper will allow you to use the first syntax and will take care of fixing the .js issue for you.
Reference on the famous issue on typescript: https://github.com/microsoft/TypeScript/issues/16577
You can run the compiler directly with
npx @webda/tsc-esm
Or add it to your project with
# NPM
npm add --dev @webda/tsc-esm
# Yarn
yarn add --dev @webda/tsc-esm
# pnpm
pnpm add --dev @webda/tsc-esm
Update your package.json to add a script
{
"scripts": {
"build": "tsc-esm"
}
}
Arize AI is a machine learning observability and model monitoring platform. It helps you visualize, monitor, and explain your machine learning models. Learn more
Loopingz is a software development company that provides consulting and development services. Learn more
Tellae is an innovative consulting firm specialized in cities transportation issues. We provide our clients, both public and private, with solutions to support your strategic and operational decisions. Learn more
FAQs
Compile with ES6 Module import correction
The npm package @webda/tsc-esm receives a total of 39 weekly downloads. As such, @webda/tsc-esm popularity was classified as not popular.
We found that @webda/tsc-esm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.