
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
node-red-contrib-simplepush
Advanced tools
Simplepush tasks, notifications and submissions for Node-RED
Simplepush nodes for Node-RED.
Run the following command in your Node-RED user directory - typically ~/.node-red
npm install node-red-contrib-simplepush
Requires Node.js 20 or newer and Node-RED 3 or newer.
| Node | What it does |
|---|---|
simplepush task | Sends a task and outputs every answer. |
simplepush notification | Sends a push with at most one answer, an image or audio clip, or a link. |
simplepush in | Outputs every submission people send from the app. |
| Simplepush account | Config node with the credentials, shared by all nodes. One connection per account. |
sp integration create. Encryption uses the organization's keys, which come with the token.Topics are created and subscribed to in the app. Leave the topic blank to send to your own devices. An organization send needs exactly one of topic, member or broadcast.
Inputs are set in the node or passed as msg.inputs, in the shape of the TypeScript SDK:
msg.inputs = [
{ type: "actions", actions: ["Approve", "Deny"] },
{ type: "text", description: "Comment", required: false },
{ type: "choice", options: ["Red", "Green", "Blue"], multi: true, maxSelections: 2 },
{ type: "slider", min: 0, max: 14, step: 0.1, unit: "pH" },
{ type: "photo" }, { type: "voiceRecording" }, { type: "file" }, { type: "location" }
];
required defaults to true. Each type at most once.
Message properties, used when the node's field is blank:
| Property | |
|---|---|
msg.payload | The message. Objects are sent as JSON. |
msg.topic, msg.member, msg.broadcast | The target. member and broadcast are for organizations. |
msg.title, msg.tag | Title and a label to group or filter by. |
msg.priority | 1 (silent) to 5 (critical, sounds on a muted phone). Default 3. |
msg.expiresIn | Seconds until an unanswered task expires. |
msg.shared | true: one task for all recipients, the first answer completes it. Default: one task per recipient. |
msg.markdown | true renders the message as Markdown. |
msg.links | Array of URLs shown with the task. |
msg.attachments | Array of files: URLs to download, or {filename, data, contentType} with data a Buffer. |
msg.autoCommit | true (default) saves each input as it is filled, false shows a Submit button. |
A boolean on the message wins over the node's checkbox.
Outputs: one message per answer. With actions in the node there is one output per action, otherwise the first output. After those, one output each for tasks that ended without an answer: declined, canceled (withdrawn by the sender), expired. A task that everyone deleted from their list ends without a message.
| Property | |
|---|---|
msg.payload | The answer: action, text, choice, choices, slider, location, and photo, voice, file as {data, filename, contentType, size} with data a Buffer. On the outputs for tasks without an answer, the status. |
msg.status | completed, declined, canceled or expired. |
msg.taskId, msg.groupId | The task, and the group of tasks when every recipient got their own. |
msg.recipient | Who answered: publicId, name. |
msg.completedAt | When the task was completed. |
msg.declines | On a declined task: who declined, in order, as {recipient, reason, note}. One entry per task sent to one recipient; everyone on a shared task. |
msg.note | The note left when declining, when one person declined. |
A push that does not stay in the app's task list. One answer at most: action buttons or a choice (up to 3 each), or text. Set in the node or as msg.input:
msg.input = { type: "actions", actions: ["Open", "Ignore"] };
msg.image or msg.audio is a URL or {filename, data, contentType}. msg.link adds an Open link button (any scheme, so an app link opens that app); not together with an answer.
A notification does not expire. Answers leave through the first output (msg.status completed). With a timeout, recipients who did not answer in time leave through the second output with msg.status pending. Without one the node waits until everyone answered or the flow is redeployed.
One message per submission: msg.payload has text, location, and photo, file, audio with data a Buffer. msg.sender, msg.submissionId, msg.submittedAt.
Flows from 1.x keep working once the node has an account:
event becomes tag, the timeout becomes Expires in, the actions become an actions input with one output per action.salt is gone. Set a password for the topic in the app and add the topic and password to the account. A password saved on a 1.x node keeps working until then.msg.payload of an answer is an object: the tapped action is msg.payload.action.msg.key and msg.password raise an error, use msg.topic and the account. msg.salt is ignored.See simplepu.sh for more details.
FAQs
Simplepush tasks, notifications and submissions for Node-RED
The npm package node-red-contrib-simplepush receives a total of 52 weekly downloads. As such, node-red-contrib-simplepush popularity was classified as not popular.
We found that node-red-contrib-simplepush demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.