
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
NoSQL local file storage with constraints -- unique keys, null check and indexing, akin to SQLite, with API similar to liteorm
NoSQL local file storage with constraints -- unique keys, null check and indexing, akin to SQLite, with API similar to liteorm. Powered by TypeScript decorators and interface. Also with async event-emitter, thanks to emittery.
Can save as BSON with BsonAdapter.
Filtering and mapping with objects (in find, update, delete) is possible, thanks to lodash.
If you need typings, you can also enforce constraints.
import { Db } from "nocon-db";
(async () => {
const db = new Db("foo.nocon");
await db.load();
const col = db.collection<any>("bar");
await col.insert({a: 1, b: new Date()});
console.log(await col.find({a: 1}));
})();
You can even define Schema and unique keys. In this case, you will need to use Class decorators.
import { Db, prop, Table, BsonAdapter } from "nocon-db";
@Table()
class UniqueA {
@prop({unique: true}) a!: string;
b!: Date;
}
(async () => {
let db = new Db("test.nocon", new BsonAdapter());
await db.load();
const col = db.collection(new UniqueA());
await col.insert({a: "any", b: new Date()});
console.log(await col.find());
await db.close();
db = new Db("test.nocon", new BsonAdapter());
await db.load();
const col = db.collection(new UniqueA());
await col.insert({a: "any", b: new Date()}); // Error
})();
FAQs
NoSQL local file storage with constraints -- unique keys, null check and indexing, akin to SQLite, with API similar to liteorm
The npm package nocon-db receives a total of 2 weekly downloads. As such, nocon-db popularity was classified as not popular.
We found that nocon-db demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.