
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
ytranscript-api
Advanced tools
Reliable YouTube transcript extraction API client — no IP bans, no proxy management, Whisper fallback for captionless videos.
Official JavaScript/TypeScript client for the yTranscript API — reliable YouTube transcript extraction without IP bans, proxy management, or player-response scraping.
npm install ytranscript-api
import { YTranscript } from "ytranscript-api";
const yt = new YTranscript("yk_live_..."); // get a key at ytranscript.com/developers
const t = await yt.transcript("dQw4w9WgXcQ"); // video ID or any YouTube URL
console.log(t.lang); // "en"
console.log(t.segments[0]); // { text, offset, duration }
console.log(t.text); // full transcript as one string
console.log(yt.lastQuota); // { limit, used, rateLimitRemaining }
await yt.transcript("https://youtu.be/dQw4w9WgXcQ", { lang: "es" });
new YTranscript(key, { timeoutMs: 60_000 });
import { YTranscriptError } from "ytranscript-api";
try {
await yt.transcript(videoId);
} catch (err) {
if (err instanceof YTranscriptError) {
err.code; // "no_transcript" | "quota_exceeded" | "rate_limited" | ...
err.status; // HTTP status
}
}
Plans start at $29/mo for 10,000 units (captions = 1 unit, Whisper = 15 units). Get an API key at ytranscript.com/developers.
MIT
FAQs
Reliable YouTube transcript extraction API client — your servers never get IP-banned, no proxy management, Whisper fallback for captionless videos.
The npm package ytranscript-api receives a total of 12 weekly downloads. As such, ytranscript-api popularity was classified as not popular.
We found that ytranscript-api demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.