
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Search 38 npm publish/EOTP, GitHub Actions, MCP, Windows and Base fixes; 12 free, USDC/ETH packs.
Connect an AI agent to the KnownFix storefront, a catalog of 38 real development-error fixes: 34 verified in production, 4 documented, and 12 available in full for free.
npx knownfix search "your exact error"
npx knownfix config claude
npx knownfix tools
npx knownfix books
npx knownfix search --json "<exact error>" now returns the complete
machine-readable search_fixes result, including its private signed checkout
when the match is paid. Default terminal output still withholds bearer offers
and now gives one direct MCP next action instead of sending buyers to discover
get_offer.
npm ERR! code EOTPEOTP is an authentication branch point, not one failure. Identify the publish path before changing credentials:
id-token: write, npm 11.5.1 or newer, and Node
22.14 or newer.Run the exact signature through the agent-readable checkout:
npx knownfix search --json "npm ERR! code EOTP"
The verified exact-fix page contains the free diagnosis. Repeated publish incidents are better served by the six-fix npm Publishing Recovery Pack for $4. The supporting field report, open books, and npm's official 2FA, Trusted Publishing, and token guidance are publicly inspectable before payment.
The hosted MCP server uses Streamable HTTP:
https://knownfix-backend-28.b-hash88.deno.net/mcp
Run npx knownfix config <client> for Claude, Cursor, Codex, VS Code,
LangChain, CrewAI, or raw JSON-RPC. npx knownfix bridge provides a local stdio
bridge for clients without remote HTTP support.
The remote server currently publishes 12 tools. Every tool includes an output
schema and behavior annotations. Paid audits are previewed and redeemed through
audit_endpoint; get_skill delivers both individual skills and assembled
multi-fix bundles; and contributors can poll the private id returned by
submit_fix with check_submission without exposing their submitted text.
Current npm CLI EOTP wording is indexed as an exact alias of the documented
2FA/authorized-publishing recovery, so agents reach the same remedy by either
the interactive EOTP or registry 403 signature.
Search and free samples require no account or API key. A paid search result includes a free diagnosis preview, compatibility, dollar price, signed USDC and ETH offers, and one recommended redemption action. For direct checkout:
get_fix with a paid fix id alone for that same purchase-ready response.get_skill with a skill or bundle id alone for its free outline, dollar
price, signed USDC and ETH offers, and one recommended redemption action.get_offer only when you need to refresh or select one rail explicitly.search_fixes, get_fix, or
get_skill; call get_offer with productType, productId, and currency
(USDC or ETH) only when you need a fresh single-rail offer.paymentOffer token private.priceWei for
ETH on Base mainnet, chain 8453.get_fix or get_skill with both paymentTx and paymentOffer.
For Base Pay, paymentTx is the returned ERC-4337 UserOperation hash. For
exact ETH, it is the mined Base transaction hash.The payment proof and offer are atomically single-use. Inspect the public books and agent-readable store guide before paying. The npm Publishing Recovery Pack bundles six fixes plus a current decision tree for $4 USDC. The GitHub Actions Failure Pack adds a failed-phase decision tree and seven workflow, permission, cache, runtime, and verification recoveries for $5 USDC. The MCP Server Operations Pack adds a dual-era stdio, Streamable HTTP, tool-contract, and official-registry runbook with four catalog fixes for $6 USDC. The Windows Agent Shell Pack supplies six PowerShell, MSYS2, Node.js, secret-prompt, and environment recoveries for $4 USDC. The Base Payment Verification Pack combines the complete EVM seller-verification skill, distinct UserOperation and transaction proof paths, durable fulfillment controls, and seven related fixes for $49 USDC.
search "<error>" — ranked match and purchase-ready checkout summarysearch --json "<error>" — complete private machine-readable resultconfig <client> — client-specific MCP configurationtools — live MCP tool listbooks — live request-to-sale funnelbridge — stdio proxy to the hosted MCP endpointRequires Node.js 18 or newer. MIT licensed.
FAQs
Search 38 npm publish/EOTP, GitHub Actions, MCP, Windows and Base fixes; 12 free, USDC/ETH packs.
We found that knownfix demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.