
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
velaris-lang
Advanced tools
This project was called Velaris until 8.6.0. The name belongs to an unrelated company in the same market (velaris.io), so it was given up rather than contested.
npm install sabline-lang
This package, velaris-lang 8.6.0, is the last release under the old name.
It holds no code: it depends on sabline-lang and re-exports it, and
sabline-lang installs both the sabline and the velaris commands, so
npx velaris hello.vel keeps working for one major version.
Every version published before this one is still on npm, unchanged.
FAQs
Renamed: Velaris is now Sabline. Installing this installs sabline-lang.
We found that velaris-lang demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.