
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
##ty-open
npm install ty-open -g
usage: to [command] [args...] [options]
commands: add, ls, rm, bak, res
add, add a site, eg: to add npm "https://www.npmjs.com/"
options: -s, -d
-s, --ssl, use "https" as the protocol, no need to specify it
-d, --default, set default url (used when no arguments are provided)
-f, --force, add a site without checking the url
ls, list sites, eg: to ls npm
options: -t
-t, --tree, will list the sites in a tree
rm, delete a site, eg: to rm npm
options: -f, -c
-f, --force, delete the site without prompt
-c, --children, only delete the children sites under the namespace
bak, export current config file, eg: to bak [path], default path is current dir
res, import config file, eg: to res <config_file_path>
options: -m
-m, --merge, merge custom config file and current config file, default is false
when command is the site name or a valid url, will open the default browser directly
eg: to npm, will open "https://www.npmjs.com"
notice: add, rm, ls, bak and res are retained for this command, you can not use them as a site name, eg: to add rm "https://..." is invalid
MIT
FAQs
Site Favorites For Terminal
We found that ty-open demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.