
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Token usage, estimated cost, and a 52-week activity dashboard for DeepSeek Harness Web
English · 简体中文
See where your tokens go. dsh-usage adds per-turn token summaries, estimated model cost, and a 52-week activity dashboard to DeepSeek Harness Web.
Community plugin maintained independently from DeepSeek. Cost is an estimate, not a provider bill.
Total · Input · Cache · Output · Cost summary below every completed turn.The plugin replays Harness's existing session log instead of creating another usage database. Local Usage remains independent from Community login and network availability.
Requirements: Node.js 22.18 or newer and an existing DeepSeek Harness Web profile.
npx --yes --package=@deepseek-ai/dsh --package=pnpm@11.9.0 -- dsh plugin --profile web add dsh-usage
npx --yes @deepseek-ai/dsh --profile web --dump-config
npx --yes @deepseek-ai/dsh --profile web
Open the Web URL printed in the terminal, complete one model response, then check the turn summary and Settings → Usage. Restart Harness after the first installation so the Web client discovers the plugin.
The commands deliberately pin the verified pnpm 11.9.0 installation baseline. pnpm 11.7.0 can fail while installing the plugin.
Upgrade, global CLI, source-checkout, proxy, and troubleshooting guide
Connect GitHub and Community Sync are separate choices. Signing in identifies your public profile; it does not start an upload. Sync stays off until you explicitly enable it in Settings → Usage.
When enabled, the plugin uploads only aggregate daily/model request and token totals. It never uploads prompts, responses, session content, tool content, paths, hostnames, hardware identifiers, or cost. Unknown/private model routes are combined into other before the request is created. A failed sync never interrupts local Usage.
Open the leaderboard and illustrated setup guide →

Input, cache read, cache write, and output remain separate buckets. Reasoning tokens already reported as output are not counted twice. Forked and sub-Agent sessions subtract inherited seed events while retaining the child's new model calls, including provider-reported cache reads.
Cost appears only when every relevant call has provider usage and a matching effective-dated rate. Otherwise token totals remain visible and cost is omitted instead of showing a misleading partial amount.
MIT licensed.
FAQs
Token usage, estimated cost, and a 52-week activity dashboard for DeepSeek Harness Web
The npm package dsh-usage receives a total of 1,037 weekly downloads. As such, dsh-usage popularity was classified as popular.
We found that dsh-usage demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.