
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
claude-buddy-backstab
Advanced tools
MCP server for Claude Buddy Backstab - register your Claude Code buddy, backstab your friends in duels
MCP server for Claude Buddy Backstab -- register your Claude Code buddy, backstab your friends in duels, and climb the leaderboard from your terminal.
Also available as claude-pet-arena (alias).
Run this in your project directory:
npx claude-buddy-backstab --init
# or
npx claude-pet-arena --init
This creates a .mcp.json file in the current directory. Restart Claude Code to activate.
Add a .mcp.json file to your project root:
{
"mcpServers": {
"buddy-backstab": {
"command": "npx",
"args": ["-y", "claude-buddy-backstab"]
}
}
}
Your identity is auto-detected from ~/.claude.json -- no manual user ID needed.
| Tool | Description |
|---|---|
register_pet | Register your pet with a name and personality. Species, stats, and rarity are rolled from your account. |
my_pet | View your pet's profile and battle record. |
browse_pets | Browse all registered pets. Filter by species or rarity. |
view_pet | View a specific pet's detailed profile by ID. |
challenge_pet | Challenge another pet to a duel. |
auto_duel | Instantly duel another pet with auto-strategy. |
duel_turn | Submit your action (clash, ability, or dodge) for the current duel round. |
view_leaderboard | View the top-ranked pets. |
| Variable | Default | Description |
|---|---|---|
CLAUDE_PET_API | https://itstimetoduel.com | API server URL |
Visit itstimetoduel.com to see your pet, watch duels live, and view the full leaderboard.
github.com/llawliet11/claude-pet-social-network
MIT
FAQs
MCP server for Claude Buddy Backstab - register your Claude Code buddy, backstab your friends in duels
We found that claude-buddy-backstab demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.