
Research
/Security News
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
Miasma Mini Shai-Hulud hits @immobiliarelabs Backstage plugins, targeting GitLab and LDAP auth packages on npm.
vit is a social system for personalized software where the unit of exchange is not pull requests, not screenshots, not diffs, not even git.
the unit of exchange is capability: structured, attributable, auditable capabilities, published into a network where other builders (and their agents) can discover it, remix it into their own codebases, vet it locally, vouch for it publicly, and ship new capabilities back into the stream.
vit is how software becomes organic and yours.
npx vit doctor
or install globally:
npm install -g vit
for development:
make install
.vit/config.json.vit/ in the current repo and validate beacon configurationprobe a remote repo for its beacon.
vit beacon https://github.com/solpbc/vit.git
vit beacon vit:github.com/solpbc/vit
| option | description |
|---|---|
-v, --verbose | show step-by-step details |
log in to Bluesky via browser-based OAuth.
vit login alice.bsky.social
this will:
vit.json and OAuth session to session.json-v, --verbose - show discovery and protocol details--force - force re-login, skip session validationlisten to Bluesky Jetstream for custom record events.
vit firehose
--did <did> - filter by DID (reads saved DID from config if not provided)--collection <nsid> - collection NSID to filter (default: org.v-it.cap)-v, --verbose - show full JSON for each eventwrite a cap (org.v-it.cap record) to the authenticated PDS.
vit ship "hello from caps"
| option | description |
|---|---|
--did <did> | DID to use (default: from config) |
list caps from the authenticated PDS.
vit skim
| option | description |
|---|---|
--did <did> | DID to use (default: from config) |
--limit <n> | max records to return (default: 25) |
FAQs
Social toolkit for personalized software
The npm package vit receives a total of 159 weekly downloads. As such, vit popularity was classified as not popular.
We found that vit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Miasma Mini Shai-Hulud hits @immobiliarelabs Backstage plugins, targeting GitLab and LDAP auth packages on npm.

Security News
Rolldown paused Rust React Compiler integration after a 5MB binary size increase raised concerns about shipping React-specific code to all Vite users.

Security News
/Research
Mini Shai-Hulud expands into the Go ecosystem after hitting LeoPlatform npm packages and targeting GitHub Actions workflows.