
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
Framework-agnostic USRCP core — encrypted ledger, crypto, pairing, identity rotation, and scope enforcement. No MCP server, no CLI.
The framework-agnostic core of USRCP — the encrypted ledger, crypto, device pairing, identity rotation, and scope enforcement, with no MCP server and no CLI.
usrcp-core is the protocol engine every other USRCP package builds on. It has
no opinion about how it's driven — the local MCP server (usrcp-local), the
capture adapters, and usrcp-stream all depend on it for the same encrypted,
structured user state. Its only runtime dependencies are better-sqlite3 and
zod.
If you just want to run USRCP, install usrcp
(npm i -g usrcp) or brew install frank-bot07/usrcp/usrcp — you don't install
usrcp-core directly. This package is for building on the protocol.
usrcp-core/ledger) — a single SQLite file where every
value is encrypted at rest (libsodium secretbox) under a master key that never
leaves the machine. Structured facts, timeline events, domain context, audit log.usrcp-core/encryption, usrcp-core/crypto) —
master-key derivation, per-domain keys, HMAC blind-index search tokens,
identity keypair management.usrcp-core/pair) — the pairing protocol (the terminal QR
rendering lives in usrcp-local, not here).usrcp-core/rotate-identity).usrcp-core/scope-enforcement) — default-deny read
projections and per-tool scoping, shared so usrcp-local and usrcp-stream
enforce identical semantics.npm install usrcp-core
better-sqlite3 is a native module; it builds on install.
import { Ledger } from "usrcp-core/ledger";
import { encrypt, decrypt, deriveDomainEncryptionKey } from "usrcp-core/encryption";
import { getIdentity } from "usrcp-core/crypto";
import { pairInit, pairJoin } from "usrcp-core/pair";
import { rotateIdentity } from "usrcp-core/rotate-identity";
import { registerToolsWithScopes } from "usrcp-core/scope-enforcement";
The barrel (usrcp-core) re-exports all of the above.
usrcp-local (which depends on this).usrcp command here — that's usrcp-local.Apache-2.0
FAQs
Framework-agnostic USRCP core — encrypted ledger, crypto, pairing, identity rotation, and scope enforcement. No MCP server, no CLI.
The npm package usrcp-core receives a total of 275 weekly downloads. As such, usrcp-core popularity was classified as not popular.
We found that usrcp-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.