
Research
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
Blimu - Authorization as a Service. This package provides the Blimu CLI tool for managing your authorization configuration and generating type-safe TypeScript types.
npm install blimu
# or
yarn add blimu
# or
pnpm add blimu
Generate type augmentation files from your Blimu configuration:
# Generate type augmentation with defaults
# Looks for .blimu/config.mjs or .blimu/config.ts in current directory
# Outputs to .blimu/blimu-types.d.ts
blimu codegen
# With custom config path
blimu codegen --config ./custom/path/config.mjs
# With custom output path
blimu codegen --output ./types/blimu-types.d.ts
# With custom SDK package
blimu codegen --sdk-package @blimu/custom-backend
# All options together
blimu codegen --config .blimu/config.mjs --output .blimu/blimu-types.d.ts --sdk-package @blimu/backend
--config <path>: Optional path to Blimu config file. If not provided, the CLI will look for .blimu/config.mjs or .blimu/config.ts in the current directory.--output <path>: Optional output path for the generated type augmentation file. Defaults to .blimu/blimu-types.d.ts.--sdk-package <name>: Optional SDK package name. Defaults to @blimu/backend.The CLI looks for a Blimu configuration file in the .blimu/ directory. The config file should export a default object with the following structure:
// .blimu/config.mjs
export default {
resources: {
workspace: {},
environment: {},
},
entitlements: {
'workspace:read': {},
'workspace:create': {},
},
plans: {
free: {
name: 'Free Plan',
resource_limits: {
workspace_count: 1,
},
},
pro: {
name: 'Pro Plan',
resource_limits: {
workspace_count: 10,
},
},
},
};
The config file can be:
.mjs (ES Module JavaScript).js (JavaScript).ts (TypeScript - requires tsx or ts-node)The codegen command generates a TypeScript declaration file that augments the @blimu/backend SDK with union types based on your configuration:
ResourceType: Union of all resource types from your configEntitlementType: Union of all entitlement types from your configPlanType: Union of all plan types from your configLimitType: Union of all resource limit types from your plansUsageLimitType: Union of all usage-based limit types from your plansThis provides full type safety and autocomplete when using the Blimu SDK in your application.
For programmatic access to the Blimu API, use the following SDK packages:
@blimu/backend - TypeScript SDK for Blimu Runtime API (resource management, roles, entitlements, usage tracking)@blimu/client - TypeScript SDK for Blimu Client API (authentication, session management)@blimu/nestjs - NestJS integration for Blimunpm install @blimu/backend
# or
npm install @blimu/client
# or
npm install @blimu/nestjs
To build the CLI from source:
yarn build
# or
npm run build
To run the CLI in development mode:
yarn dev
# or
npm run dev
Visit https://blimu.com for documentation and more information.
FAQs
Blimu - Authorization as a Service CLI
The npm package blimu receives a total of 121 weekly downloads. As such, blimu popularity was classified as not popular.
We found that blimu demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.