
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
dsh-db-browser
Advanced tools
dsh 数据库浏览插件:会话顶部「数据库」视图 Tab,多连接管理、点表分页浏览,只读多层防护,驱动注册表架构目标支持尽可能多的数据库,dsh plugin add 一条命令安装
DSH(DeepSeek Harness) 的只读数据库浏览器插件:在会话顶部增加一个「数据库」视图 Tab,与 聊天/轨迹 并排,直接浏览数据库数据,零构建、纯主题 token 样式。
--dsw-alias-* 主题 token,暗色/亮色自动跟随,无硬编码颜色。文件型数据库填绝对文件路径(~ 开头会展开);服务型数据库填 URI 或 键=值; 风格连接串(自动转换,密码自动编码),侧栏展示时密码隐藏为 ***。
dsh plugin --profile web add dsh-db-browser
# 或从 GitHub 安装:dsh plugin --profile web add github:fengb3/dsh-db-browser
重启 dsh web,会话顶部即出现「数据库」Tab。需装有 pnpm;非默认 profile 换掉 --profile 名字即可。
把下面整段文本复制,粘贴给你正在使用的 DSH agent,它会替你完成安装:
请帮我安装 DSH 插件 dsh-db-browser(只读数据库浏览器,装好后会话顶部会多一个「数据库」Tab,与 聊天/轨迹 并排):
1. 执行:dsh plugin --profile web add dsh-db-browser(若我明确说了用别的 profile,把 web 换成对应名字;执行失败的完整报错原样发给我,不要自行重试超过一次;失败时可改用 dsh plugin --profile web add github:fengb3/dsh-db-browser 再试一次)。
2. 完成后告诉我需要手动重启 dsh web 才生效(你自己不要尝试重启 dsh web,那会终止你所在的会话)。重启后会话顶部应出现「数据库」Tab;若启动报错,把 dsh web 的错误日志发给我排查。
dsh plugin --profile web remove dsh-db-browser
重启 dsh web。连接清单保存在 $DSH_HOME/db-browser/connections.json,删除该目录即彻底清除。
index.js host 半:dbBrowser Typert Remote 服务(连接存储、驱动、查询守卫)
client.js 浏览器半:conversation.view Tab + 连接/表/结果 UI(loader 格式,零构建)
cordis.patch.yml bundle 声明:`dsh plugin add` 据此自动登记为 profile 层
package.json dsh.bundle.patch + dsh.client.inject 声明
host 半在 DRIVERS / ALLOWED_STATEMENTS 登记类型与白名单,实现 probe / tables / columns / query;client 半在 DRIVERS 登记 label、占位符、提示与标识符引用符。
MIT
FAQs
dsh 数据库浏览插件:会话顶部「数据库」视图 Tab,多连接管理、点表分页浏览,只读多层防护,驱动注册表架构目标支持尽可能多的数据库,dsh plugin add 一条命令安装
We found that dsh-db-browser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.