
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
tako-remote
Advanced tools
Code on the go — control AI coding agents from your phone, browser, or terminal.
Free. Open source. Code anywhere.
npm install -g happy
Migrated from the
happy-coderpackage. Thanks to @franciscop for donating thehappypackage name!
happy
# or
happy claude
This will:
happy codex
happy gemini
happy openclaw
# or any ACP-compatible CLI
happy acp opencode
happy acp -- custom-agent --flag
The daemon is a background service that stays running on your machine. It lets you spawn and manage coding sessions remotely — from your phone or the web app — without needing an open terminal.
happy daemon start
happy daemon stop
happy daemon status
happy daemon list
The daemon starts automatically when you run happy, so you usually don't need to manage it manually.
If you want the daemon to come back automatically after a reboot — without opening a happy session first — start it from your shell profile so it inherits your normal user session context (PATH, keychain access, OAuth credentials):
# ~/.zshrc or ~/.bashrc
if [[ -o interactive ]] && [[ -z "$HAPPY_DAEMON_CHECKED" ]]; then
export HAPPY_DAEMON_CHECKED=1
() {
local state=$HOME/.happy/daemon.state.json
local pid=$(grep -oE '"pid"[[:space:]]*:[[:space:]]*[0-9]+' "$state" 2>/dev/null | grep -oE '[0-9]+')
if [[ -z "$pid" ]] || ! kill -0 "$pid" 2>/dev/null; then
happy daemon start >/dev/null 2>&1
fi
} &!
fi
The first interactive shell after a reboot triggers the start; subsequent shells short-circuit because the daemon is already running.
macOS users: prefer this shell-init approach over a
launchdLaunchAgent. A LaunchAgent runs in an agent domain that is detached from your GUI/Aqua login session, which means the bundledclaude-agent-sdkcannot reach the macOS keychain and silently fails authentication ("Failed to authenticate. API Error: 401 terminated",duration_api_ms: 0). If you must use launchd, your wrapper has to read the OAuth access token from~/.claude/.credentials.jsonand export it asCLAUDE_CODE_OAUTH_TOKENbefore exec'ing the daemon — and you'll need to handle token rotation yourself.
happy auth login
happy auth logout
Happy uses cryptographic key pairs for authentication — your private key stays on your machine. All session data is end-to-end encrypted before leaving your device.
To connect third-party agent APIs:
happy connect gemini
happy connect claude
happy connect codex
happy connect status
| Command | Description |
|---|---|
happy | Start Claude Code session (default) |
happy codex | Start Codex mode |
happy gemini | Start Gemini CLI session |
happy openclaw | Start OpenClaw session |
happy acp | Start any ACP-compatible agent |
happy resume <id> | Resume a previous session |
happy notify | Send push notification to your devices |
happy doctor | Diagnostics & troubleshooting |
| Variable | Description |
|---|---|
HAPPY_SERVER_URL | Custom server URL (default: https://api.cluster-fluster.com) |
HAPPY_WEBAPP_URL | Custom web app URL (default: https://app.happy.engineering) |
HAPPY_HOME_DIR | Custom home directory for Happy data (default: ~/.happy) |
HAPPY_DISABLE_CAFFEINATE | Disable macOS sleep prevention |
HAPPY_EXPERIMENTAL | Enable experimental features |
Happy can run agents inside an OS-level sandbox to restrict file system and network access.
happy sandbox configure
happy sandbox status
happy sandbox disable
git clone https://github.com/slopus/happy
cd happy-cli
yarn install
yarn workspace happy cli --help
claude CLI installed & logged incodex CLI installed & logged innpm install -g @google/gemini-cli + happy connect geminiMIT
FAQs
Tako remote control for Claude Code and Codex
We found that tako-remote demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.