
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
grain-tools
Advanced tools
Name reservation for Grain — a local SQL execution layer for coding agents. Not yet released; see https://grain.tools
Reserved for Grain — a local SQL execution layer that coding agents can drive over MCP, a CLI, or the VS Code extension.
Nothing is published here yet. This version reserves the name while the first release is prepared. When it ships, this package will provide the stdio MCP server:
{
"mcpServers": {
"grain": {
"command": "npx",
"args": ["-y", "grain-tools", "--stdio"]
}
}
}
The primary install path will be a standalone binary from
grain.tools, which needs no Node.js and reduces the
configuration above to "command": "grain". This package is the fallback channel
for anyone who would rather use npm.
FAQs
Standalone Grain MCP database server for VS Code, Claude Desktop, Cursor, and other MCP clients.
The npm package grain-tools receives a total of 0 weekly downloads. As such, grain-tools popularity was classified as not popular.
We found that grain-tools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.