
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Offline Rust secret scanner for source code and Git history, with JSON, SARIF and MCP for AI agents
Keyspoor finds API keys, passwords and other credentials in source code, local Git history and supported archives. Its independent Rust engine includes 225 rules, redacted findings, baseline support, JSON/JSONL/SARIF output and an MCP stdio server for AI agents.
This npm package provides the native command-line tool, not a JavaScript SDK. For the Rust library, source, rule provenance and measured benchmarks, see the Keyspoor repository.
npm install --global keyspoor
keyspoor scan . --format json
keyspoor staged .
keyspoor history .
keyspoor scan - --format jsonl
keyspoor mcp --root /absolute/path/to/project
You can also run npx keyspoor scan . --format sarif without a global
installation. A standalone npm-format tarball is available on GitHub Releases.
The package bundles native binaries for Linux x64/ARM64 (GNU libc), macOS x64/ARM64 and Windows x64. Node.js 20 or later is required for the launcher. It has no install scripts, install-time binary downloads or runtime JavaScript dependencies. Alpine/musl and Windows ARM64 are not supported by these binaries. Linux builds use Ubuntu 24.04 and dynamically link glibc; older glibc systems are not guaranteed to run them. See the release guide. Git must be installed for staged and history scans.
Exit codes are 0 for a completed scan with no reported findings, 1 for a completed scan with findings, and 2 for errors or an incomplete scan. The launcher passes arguments and standard streams directly to the Rust CLI.
Scanning is offline and does not verify whether credentials are active. Findings are redacted; the scanner does not print raw secrets. Detection has false positives and false negatives; a clean result is not proof that an input contains no secrets. See the documentation for scan limits, ignore behavior, custom rules and baseline semantics.
Apache-2.0. Adapted Gitleaks rule data retains its MIT license and attribution in
THIRD_PARTY_NOTICES.
FAQs
Offline Rust secret scanner for source code and Git history, with JSON, SARIF and MCP for AI agents
The npm package keyspoor receives a total of 308 weekly downloads. As such, keyspoor popularity was classified as not popular.
We found that keyspoor demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.