
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Put your app online straight from your computer. No GitHub, no Docker, no setup.
Point the CLI at a project folder and it uploads your code, builds it, and gives you a live URL. If your project has a Dockerfile it uses that. If it does not, Dockhold detects your stack and builds it for you.
npx dockhold login
npx dockhold deploy
login opens your browser once to connect your Dockhold account. deploy packs
the current folder, uploads it, and prints your app's URL when it is live. Run
deploy again any time to push a new version.
dockhold login [--token [<token>]] Sign in (a bare --token prompts for a
paste, keeping it out of shell history)
dockhold deploy [--name <name>] Deploy the current folder
[--env KEY=VALUE ...] Set an environment variable (repeatable)
[--db] Add a managed database
dockhold logs [--app <id>] Show recent logs
[--tail <n>] [--type app|build|db]
dockhold list List your apps
dockhold open [--app <id>] Open an app in your browser
The CLI packs your project folder, with a few things always left out:
.git and node_modules.env file (see below).gitignore excludesYou can add a .dockholdignore file (same format as .gitignore) to exclude
more. It takes priority over .gitignore.
Your .env files are never uploaded. Set variables on the deploy instead:
npx dockhold deploy --env DATABASE_URL=... --env API_KEY=...
You can also manage them in the dashboard. They are stored encrypted and injected into your app at runtime.
The CLI talks to Dockhold's hosted service by default. These environment variables override that when you need to:
DOCKHOLD_TOKEN — use this access token instead of the signed-in oneDOCKHOLD_API_URL — point at a different API endpointDOCKHOLD_DASHBOARD_URL — point sign-in at a different dashboardYour access token is stored in ~/.config/dockhold/config.json with owner-only
permissions.
Node.js 18 or newer.
FAQs
Deploy an app to Dockhold from your computer or your AI tool. No GitHub, no Docker.
The npm package dockhold receives a total of 240 weekly downloads. As such, dockhold popularity was classified as not popular.
We found that dockhold demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.