
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
MCP server for TDCv2: agents write a .tdc config, check it and generate test data locally — deterministic, same seed, same bytes.
An MCP server that lets an AI agent make test data with TDCv2:
the agent writes a small .tdc config, the engine generates the rows on your machine,
and the same config gives the same file byte for byte on every run. Nothing is sent
anywhere — the server only runs the engine locally.
It is the same knowledge as the TDCv2 skill, as tools — for clients without a terminal, or
that prefer tools to skills. The skill itself ships in this package:
npx -y tdcv2-mcp@0.1.2 install-skill puts it where your agent looks for skills (--help for
the options).
Claude Code:
claude mcp add tdcv2 -- npx -y tdcv2-mcp@0.1.2
Claude Desktop, Cursor and other clients — the usual mcpServers entry:
{ "mcpServers": { "tdcv2": { "command": "npx", "args": ["-y", "tdcv2-mcp@0.1.2"] } } }
Windows: use "command": "npx.cmd" if the client cannot start npx.
The server works in the folder the client starts it in — the project. It reads .tdc
files and writes generated files only inside that folder.
| tool | what it does |
|---|---|
tdc_read_docs | the guide (read once), traps check does not catch, test code in five languages, any reference page |
tdc_find_packs | data packs installed here, by words — the paths for <gen type="template"> |
tdc_check | every diagnostic with code, line, column, hint and "did you mean" |
tdc_generate | preview (at most 50 lines) or write the file; a failed <assert> comes back as row, message, condition, values |
tdc_peek | a short summary of a CSV, JSON or SQL file — rows, splits, ranges |
tdc_format | pretty-print a config like tdcv2 format |
Also a prompt, tdcv2_guide, and resources tdcv2://guide, tdcv2://traps,
tdcv2://from-code.
The project's own tdcv2 if it has one (npm i -D tdcv2@0.3.3), then one on PATH, else the
server's own dependency. TDCV2_ENGINE=<package folder> pins one.
test/smoke.mjs drives the server through a real MCP client over stdio — every tool, the
prompt, a resource — and checks that the file it writes is byte for byte the one the CLI
writes. CI runs it on Linux and Windows.
FAQs
MCP server for TDCv2: agents write a .tdc config, check it and generate test data locally — deterministic, same seed, same bytes.
The npm package tdcv2-mcp receives a total of 313 weekly downloads. As such, tdcv2-mcp popularity was classified as not popular.
We found that tdcv2-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.