
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
deechat-ai-chat
Advanced tools
A focused AI chat client for handling AI requests and tool calling in Node.js applications
A focused AI chat client for handling AI requests and tool calling in Node.js applications.
@ai-chat is designed with a clear focus on core AI interaction:
This package does NOT handle:
context-manager)context-manager)context-manager)mcp-client or custom providers)import { AIChat } from '@ai-chat/core'
// Create AI chat client
const aiChat = new AIChat({
provider: 'openai',
apiKey: process.env.OPENAI_API_KEY,
model: 'gpt-4'
})
// Send messages (you manage the conversation history)
const messages = [
{ role: 'user', content: 'Hello!' }
]
const response = await aiChat.sendMessage(messages)
console.log(response.message.content)
class AIChat {
constructor(config: AIChatConfig)
// Send message and get complete response
sendMessage(
messages: Message[],
options?: ChatOptions
): Promise<ChatResponse>
// Send message and get streaming response
sendMessageStream(
messages: Message[],
options?: ChatOptions
): AsyncIterable<ChatStreamChunk>
}
interface AIChatConfig {
provider: 'openai' | 'claude' | 'gemini' | string
apiKey: string
model?: string
baseUrl?: string
temperature?: number
maxTokens?: number
}
// Tools are provided as input, not discovered by this package
const response = await aiChat.sendMessage(messages, {
tools: [
{
name: "search_files",
description: "Search for files",
parameters: { /* JSON Schema */ }
}
],
onToolCall: async (call) => {
// Your tool execution logic here
// This could call mcp-client, local functions, etc.
return {
toolCallId: call.id,
result: await executeMyTool(call.name, call.arguments)
}
}
})
const stream = aiChat.sendMessageStream(messages, {
tools: myTools,
onToolCall: handleToolCall
})
for await (const chunk of stream) {
if (chunk.content) {
process.stdout.write(chunk.content)
}
if (chunk.toolCalls) {
console.log('AI wants to call tools:', chunk.toolCalls)
}
if (chunk.done) {
console.log('\nResponse complete!')
break
}
}
This package is designed to work alongside other focused packages:
// Example: Complete DeeChat integration
import { AIChat } from '@ai-chat/core'
import { ContextManager } from '@context-manager'
import { MCPClient } from '@mcp-client'
// Each package handles its own responsibility
const aiChat = new AIChat(aiConfig) // AI communication
const contextManager = new ContextManager() // History & state
const mcpClient = new MCPClient() // Tool implementation
// Compose them together
const sessionId = 'session-123'
const history = contextManager.getMessages(sessionId)
const response = await aiChat.sendMessage(
[...history, { role: 'user', content: userInput }],
{
tools: await mcpClient.getTools(),
onToolCall: (call) => mcpClient.executeTools(call)
}
)
// Update context with response
contextManager.addMessage(sessionId, response.message)
npm install @ai-chat/core
# Peer dependencies (install the providers you need)
npm install openai anthropic # for AI providers
We welcome contributions! Please see our Contributing Guide.
MIT License - see LICENSE file for details.
FAQs
A focused AI chat client for handling AI requests and tool calling in Node.js applications
We found that deechat-ai-chat demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.