
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
permission-core
Advanced tools
Fine-grained RBAC and resource permission core for Node.js, with route permissions, data scopes, role inheritance, and wildcard matching.
Documentation | Quick Start | Examples | Changelog
permission-core is a tenant-aware authorization core for Node.js. It persists RBAC state through the host's MonSQLize 3.1 instance and uses one action + resource model for routes, menus, backend APIs, database rows, and fields.
npm install permission-core monsqlize@3.1.0
The root and permission-core/match entries support Node.js >=18.0.0. The optional permission-core/plugins/vext entry inherits Vext 0.3.26's stricter Node.js >=20.19.0 requirement.
import MonSQLize from 'monsqlize';
import { PermissionCore } from 'permission-core';
const msq = new MonSQLize({
type: 'mongodb',
databaseName: 'app',
config: { uri: 'mongodb://127.0.0.1:27017' },
});
await msq.connect();
const pc = new PermissionCore({ monsqlize: msq });
await pc.init();
const scope = { tenantId: 'acme' };
const scoped = pc.scope(scope);
await scoped.roles.create({ id: 'order-reader', label: 'Order reader' });
await scoped.roles.allow('order-reader', {
action: 'invoke',
resource: 'GET:/api/orders',
});
await scoped.userRoles.assign('u-1', 'order-reader');
const subject = pc.forSubject({ userId: 'u-1', scope });
console.log(await subject.can('invoke', 'GET:/api/orders')); // true
console.log(await subject.cannot('invoke', 'DELETE:/api/orders')); // true
await pc.close();
await msq.close();
cannot(...) is the logical negation of can(...); the DELETE result is true because no allow rule exists, not because a blocked permission was assigned.
permission-core/plugins/vext for hosts on Node.js >=20.19.0The application owns authentication, trusted subject construction, the MonSQLize connection, business data, HTTP serialization, and operational policy. permission-core owns authorization state and decisions. It does not implement login, expose a generic database adapter layer, or close the host database connection.
npm run example:basic
npm run example:multi-tenant
npm run example:data-guard
npm run example:menu-admin
npm run example:vext
Run all five with npm run example:all. Each emits stable JSON and uses an in-memory Mongo replica set only as a repository fixture; production applications pass their existing connected MonSQLize 3.1 instance.
Repository validation and release commands are documented separately in CONTRIBUTING.md. Security reports follow SECURITY.md.
FAQs
Fine-grained RBAC and resource permission core for Node.js, with route permissions, data scopes, role inheritance, and wildcard matching.
The npm package permission-core receives a total of 15 weekly downloads. As such, permission-core popularity was classified as not popular.
We found that permission-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.