
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
dsh-mcp-context7
Advanced tools
Context7 MCP for DeepSeek Harness: up-to-date library documentation and code examples
Context7 MCP for DeepSeek Harness. Connects the Context7 MCP server through the harness's @deepseek-ai/dsh-mcp-client bridge and exposes its tools as mcp__context7__*, giving the model up-to-date, version-specific library documentation and code examples.
dsh plugin --profile web add dsh-mcp-context7
dsh web
Or follow GitHub (latest commit):
dsh plugin --profile web add github:pymodel/dsh-research-plugins#path:packages/dsh-mcp-context7
Context7 works without a key. For higher rate limits, get a key at context7.com and expose it as an env var or in a .env file:
CONTEXT7_API_KEY=...
The row stays enabled either way; an empty key simply means keyless.
The model sees the Context7 tools under the context7 namespace (for example mcp__context7__resolve-library-id and mcp__context7__query-docs).
dsh plugin --profile web remove dsh-mcp-context7
Do not commit real keys. If your profile's cordis.patch.yml already inserts its own Context7 MCP row (id mcp-context7 or serverName context7), DSH will not boot with both: delete that row, or turn it into an override of mcp-context7 (see Already have your own MCP row?).
FAQs
Context7 MCP for DeepSeek Harness: up-to-date library documentation and code examples
The npm package dsh-mcp-context7 receives a total of 307 weekly downloads. As such, dsh-mcp-context7 popularity was classified as not popular.
We found that dsh-mcp-context7 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.