
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
prooflane-studio-cmp
Advanced tools
The mobile eyes: preview registry, headless render, live inspector. Providers behind the console's interfaces.
prooflane-studio-cmpReserved, not released. Held for the prooflane harness: a stack-agnostic verify lane that derives done from evidence rather than taking an agent's word for it.
The mobile eyes: preview registry, headless render, live inspector. Providers behind the console's interfaces.
Nothing useful installs from here yet. What works today:
npx create-cmp-cli --help
The names are claimed ahead of the code deliberately. The harness is being split
out of create-cmp-cli, and the CLI, the receipt format and every stack profile
have to agree on one name — renaming a published evidence format twice is worse
than reserving the name once. This project uses unscoped prooflane-* names
because the @prooflane organisation was unavailable.
MIT.
FAQs
The mobile eyes: preview registry, headless render, live inspector. Providers behind the console's interfaces.
We found that prooflane-studio-cmp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.