
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
Inspired by agadoo lib
Is your project 100% tree-shakeable?
With treeshake, you can find out which files and code lines that are not tree-shakeable.
Simply run npx treeshake in your project root. Make sure you have your entry point defined in package.json under either "module" or "main".
Upon running, you'll get notification whether your code is 100% tree-shakeable or not. If not, it will tell which file(s) are causing/ affected by side-effects and the codes that caused it.
********** reading files **********
tree88shakey
TREESHAKEtRe eSha
kETREESHaKetreeshAKE
TreeShakEY o0o tREeSHAKE
Es6 /T r eesHakeY
\/// /Thanks
\//////
|||||
|||||
|||||
.....//||||\....
Awesome! Your code is 100% tree-shakeable!
or
********** reading files **********
Unshaken files:
/path/to/your/file.js
/another/path/to/your/file.js
********** reading codes **********
Unshaken codes:
console.log("Side-effects");
********** Finished Reading **********
import and exportFAQs
Test if a package is 100% tree-shakeable
We found that tree-shake demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.