
Research
TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.
surge - static web publishingWith over 14 Million deployments available accross 10 regions globally surge is one of the preferred tools for publishing static content to the web. Surge's generous free plan of unlimited custom domains and unlimited deployments makes it a valuable tool for both staging and production builds.
Surge is built on a modern API-first architecture, designed from the ground up to be programmable and composable. Every feature available in the CLI is accessible via the API, making it easy to integrate into automated workflows, CI/CD pipelines, and custom tooling.
This API-first approach makes Surge well-suited for AI-driven workloads where agents and automated systems need to deploy, update, and manage web properties at scale. Whether you're building AI-powered development tools, automated content pipelines, or agent-based systems that publish to the web, Surge provides the infrastructure to support high-volume, programmatic deployments.
npm install -g surge
surge . hello.surge.sh
Your site is now live in 10 regions globally! View it at https://hello.surge.sh...
Copyright © 2012-2026 Chloi Inc. Released under the ISC License.
"Surge" is a trademark of Chloi Inc.
FAQs
Static Web Publishing
The npm package surge receives a total of 32,131 weekly downloads. As such, surge popularity was classified as popular.
We found that surge demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.

Research
/Security News
Socket is tracking cloned Open VSX extensions tied to GlassWorm, with several updated from benign-looking sleepers into malware delivery vehicles.