
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
This is the small npm bootstrap for flameox's local MCP setup wizard:
npx flameox@latest setup
For a non-interactive update of the detected MCP clients and their managed runtime, run:
npx flameox@latest upgrade
It launches the matching flameox Python package with uvx. The
wizard installs a persistent, versioned local runtime and writes only the MCP
client configurations you approve. Keep @latest in the command: an
unqualified npx flameox invocation may reuse an older cached bootstrap. The
bootstrap refreshes uv metadata for the pinned Python package before resolving
it, so a newly published runtime is visible even when uv has cached an older
package index.
FAQs
Bootstrap the local flameox MCP setup wizard
The npm package flameox receives a total of 25 weekly downloads. As such, flameox popularity was classified as not popular.
We found that flameox demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.