
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
node-red-contrib-simplepush
Advanced tools
Simplepush API wrapper for Node-RED.
Run the following command in your Node-RED user directory - typically ~/.node-red
npm install node-red-contrib-simplepush
msg.payload(required): The message of the notificationmsg.key: Simplepush key (can be found in the app) that identifies the device the notification is sent tomsg.title: The title of the notificationmsg.event: The event of the notificationmsg.actions: Array of strings that will be shown as notification actionsmsg.timeout: Time in seconds after which a feedback timeout error will be thrown. Set this to 0 if there should be no timeout. Setting this will enable forwarding of the selected action to the output of the node.msg.password: Password (can be set in the app) for encrypted notificationsmsg.salt: Salt (can be found in the app) for encrypted notificationsSee Simplepush.io for more details.
FAQs
Simplepush tasks, notifications and submissions for Node-RED
The npm package node-red-contrib-simplepush receives a total of 143 weekly downloads. As such, node-red-contrib-simplepush popularity was classified as not popular.
We found that node-red-contrib-simplepush demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.