
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
github.com/drnic/bom-charts
Advanced tools
The http://www.bom.gov.au site isn't designed for mobile devices and its images cannot be permanently linked. This site is an optimisation for some of its graphs or information.
Visit https://bom-charts.cfapps.io/gaf in your mobile device.
Click on an area of the map.

Add the dedicated GAF page to place an icon on your mobile home screen.

If an AIRMET is published that affects your area it will be displayed at the top of the page.

Visit https://bom-charts.cfapps.io/synoptic to see the 4-day forecast via synoptic charts. You can bookmark this page for quick reference.
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.