
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-security
Advanced tools
Security engineer role preset - name reserved; first release in development.
Security engineer role preset - a plugin for the DeepSeek Harness (dsh).
This package name is reserved; the first release is in development.
The adversarial persona - threat modeling, dependency audits, and secrets hygiene; pairs with dsh-secrets and dsh-policy.
Source and roadmap live in the dsh-plugin monorepo. Watch the repo or the npm package to catch the release. Related releases from the same suite: dsh-workflow, dsh-selfrepair, dsh-finder.
MIT
FAQs
Security engineer role preset - name reserved; first release in development.
We found that dsh-security demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.