
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
create-mobile
Advanced tools
The honest front door to a new mobile app. `npm create mobile` recommends Kotlin/Compose Multiplatform as the modern default, states the real trade-offs vs React Native/Flutter, and lets you choose — then, if you continue, scaffolds a green-building Andro
The honest front door to a new mobile app.
npm create mobiledoesn't silently pick a framework for you — it opens with Kotlin/Compose Multiplatform as the modern default, states the real trade-offs vs React Native and Flutter, and lets you choose. Continue, and it scaffolds a green-building Android + iOS app viacreate-cmp-cli.
npm create mobile@latest my-app
Claude Code users: the same engine ships as a plugin — /plugin marketplace add kvdm-co-pilot/create-cmp then /plugin install create-cmp (11 skills, incl. an honest
CMP-vs-React-Native/Flutter fit check, plus the cmp-inspector MCP server).
"mobile" is framework-neutral, so a package under that name that quietly stamped one stack would be a bait-and-switch. This one is built to earn the generic name. Launch it and it opens with an honest positioning:
Here's Compose Multiplatform as the modern default — one statically-typed codebase, real native Android + iOS UI, Google-backed, iOS stable since May 2025 — and here are the real trade-offs vs React Native/Flutter (bigger RN/Flutter ecosystems and hiring pools; a JS bridge or Dart's non-native render layer; CMP is the youngest of the three). You choose.
That's the same step-0 fit check the create-cmp Claude Code plugin's cmp-new skill runs,
brought to the command line. The generic name raises the honesty bar; this is how it's
cleared — you become the honest front door to mobile, not a redirect. The full sourced case
for choosing CMP (with its weaknesses named, not just its strengths) is
docs/WHY-CMP.md.
Continue with Compose Multiplatform? [Y/n]. Decline and nothing is written; it points
you at npm create expo (React Native) or flutter create and exits cleanly.--yes or piped): you've already chosen by how you invoked
it, so it prints the honest note and proceeds — no blocking prompt.--help / --version: pass straight through to the real CLI.One command stamps a frozen, CI-verified template — deterministic output, never LLM-freehanded project code:
create-cmp add firebase. --verify builds the app before
reporting success; the CLI exits non-zero on failure.node qa/verify.mjs), evidence receipts bound to a content hash, a
device-free preview loop so coding agents see what they build, and CI that refuses "done"
without proof. See it working in the
public showcase repo — including
a PR the harness refuses.An official alias for create-cmp-cli, published by the same maintainer so the
conventional npm create mobile invocation works. It adds exactly one thing of its own —
the honest fit check above — then delegates to the installed create-cmp-cli, forwarding
all arguments, stdio, and the exit code. After the choice, either name runs the same tool
with the same flags.
Fully non-interactive (scripts and AI agents):
npx create-mobile my-app --name Acme --package com.acme.app --yes --verify
npx create-mobile --helpFAQs
The honest front door to a new mobile app. `npm create mobile` recommends Kotlin/Compose Multiplatform as the modern default, states the real trade-offs vs React Native/Flutter, and lets you choose — then, if you continue, scaffolds a green-building Andro
We found that create-mobile demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.