
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
gh-trending
Advanced tools
[](https://codeclimate.com/github/rodrigogs/ilsap) [](https://david-dm.org/rodrigogs/ilsap) [![devDependen
Since Jetbrains started to blacklist license servers by hostname, it's being a pain in the ass to find a working one. So this is an active proxy for Intellij license servers, that masks a license server into your localhost.
Just create a startup script to call ilsap, configure your IDE to activate from the localhost and YOLO!
node 7.6 > required
$ npm install ilsap -g
$ ilsap --help
Usage: ilsap [options]
Options:
-V, --version output the version number
-h, --host <host> hostname to listen on (default: 0.0.0.0)
-p, --port <port> port to listen on (default: 8997)
-s, --server <server> license server url (default: http://xidea.online)
-n, --ngrok start a ngrok server pointed to your local port
-h, --help output usage information
$ ilsap
Starting server...
Listening on http://0.0.0.0:8997 <- Use this url to register your product
Redirecting requests to http://xidea.online
![]()
If xidea.online doesn't work for you, try the following servers:
I don't really give a fuck about disclaimers, intellectual property or code of conduct for open source projects(mainly), so... just use it as you want to.
FAQs
[](https://codeclimate.com/github/rodrigogs/ilsap) [](https://david-dm.org/rodrigogs/ilsap) [
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.