
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
devchain-cli
Advanced tools
AI driven development platform
Devchain coordinates AI coding agents (Claude, Codex) through a visual workflow interface with tmux-backed terminal sessions.
brew install tmuxsudo apt install tmuxclaude CLIcodex CLInpm install -g devchain-cli
Or with pnpm:
pnpm add -g devchain-cli
# Start Devchain (opens browser automatically)
devchain start
# Start in foreground with logs
devchain start --foreground
# Start on a specific port
devchain start --port 5000
# Start with a specific project
devchain start --project /path/to/your/project
# Stop the server
devchain stop
| Option | Description |
|---|---|
-p, --port <number> | Port to run on (default: 3000 or next available) |
-f, --foreground | Run in foreground with visible logs |
--no-open | Don't open browser automatically |
--db <path> | Custom database directory path |
--project <path> | Open with a specific project path |
devchain --help
Elastic License 2.0 — Free to use. You may not provide this software as a managed service or competing commercial offering.
FAQs
AI driven development platform
The npm package devchain-cli receives a total of 355 weekly downloads. As such, devchain-cli popularity was classified as not popular.
We found that devchain-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.