
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
trustsource
Advanced tools
x402-powered intelligence APIs for AI agents. Pay per use, no API keys, no accounts.
npm install
cp .env.example .env
Open .env and set at minimum:
PAY_TO_ADDRESS=0xYourBaseWalletAddress
Leave everything else as-is to run on Base Sepolia testnet (no real money).
npm run dev
You should see the startup banner at http://localhost:3000.
curl http://localhost:3000/
curl http://localhost:3000/health
curl http://localhost:3000/trustscore?domain=example.com
# Returns HTTP 402 with payment instructions in the PAYMENT-REQUIRED header
The x402 testnet facilitator at https://facilitator.x402.org accepts test payments.
To fully test the payment flow, use an x402 client with a funded testnet wallet.
Get Base Sepolia testnet ETH: https://sepolia.base.org/faucet
Get testnet USDC: https://faucet.circle.com (select Base Sepolia)
In .env, change:
NETWORK=eip155:8453
FACILITATOR_URL=https://api.cdp.coinbase.com/platform/v2/x402
CDP_API_KEY_ID=your-key-id
CDP_API_KEY_SECRET=your-key-secret
Make sure your PAY_TO_ADDRESS Base wallet has some ETH for gas.
Your endpoints auto-list in the Bazaar/Agentic.Market after the first paid call clears.
GET /trustscoreReturns a 0–100 trust score for any domain.
Payment: 0.003 USDC per call (via x402)
Params:
?domain=example.com — bare domain?url=https://example.com/some/path — full URL (domain extracted)Response:
{
"domain": "example.com",
"score": 80,
"maxScore": 100,
"tier": "TRUSTED",
"breakdown": {
"domainAge": 30,
"tld": 20,
"dnsPresence": 30,
"registrar": 20
},
"details": {
"age": { "days": 9720, "label": "established (5+ years)", "created": "...", "expires": "..." },
"tld": ".com",
"dns": { "hasARecord": true, "hasMxRecord": true, "mxRecords": ["mail.example.com"] },
"registrar": "GoDaddy"
},
"meta": {
"checkedAt": "2026-05-22T12:00:00.000Z",
"apiVersion": "1.0",
"paidWith": "x402/USDC"
}
}
Tiers:
| Score | Tier |
|---|---|
| 75–100 | TRUSTED |
| 50–74 | MODERATE |
| 25–49 | CAUTION |
| 0–24 | HIGH_RISK |
agentbrain/
├── src/
│ ├── server.ts # Express app + x402 middleware
│ └── routes/
│ └── trustscore.ts # Domain analysis logic
├── .env.example
├── .env # Your config (git-ignored)
├── package.json
└── tsconfig.json
FAQs
x402-powered intelligence APIs for AI agents
The npm package trustsource receives a total of 2 weekly downloads. As such, trustsource popularity was classified as not popular.
We found that trustsource demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.