
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
A CLI for installing Ionbit UI components into your React project.
npx ionbit-ui@latest init
npx ionbit-ui@latest add button
initInitialize Ionbit UI in your project. Creates a config file, sets up directories, installs base utilities and design tokens, and adds CSS imports.
npx ionbit-ui@latest init
Options:
--yes — skip confirmation prompts and use defaults--force — force overwrite of existing configuration--pointer — add cursor: pointer to buttons (Tailwind v4 changed the default)add <component...>Install one or more components from the registry. Automatically resolves transitive dependencies and installs npm packages.
npx ionbit-ui@latest add button
npx ionbit-ui@latest add dialog accordion glow
Options:
--overwrite — overwrite existing fileslistList all available components in the registry.
npx ionbit-ui@latest list
The CLI auto-detects your package manager from lockfiles and uses the correct install command:
| Package manager | Lockfile | Install command |
|---|---|---|
| pnpm | pnpm-lock.yaml | pnpm add |
| npm | (default) | npm install |
| yarn | yarn.lock | yarn add |
| bun | bun.lockb / bun.lock | bun add |
MIT
FAQs
Ionbit UI CLI — install source-owned components from the Ionbit UI registry.
The npm package ionbit-ui receives a total of 5,684 weekly downloads. As such, ionbit-ui popularity was classified as popular.
We found that ionbit-ui demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.