
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@audius/stems
Advanced tools
An audio-forward React Component library built with ❤️ from the team @Audius.
🚧 Actively under development, not recommended for production use! 🚧
npm install --save @audius/stems
import React from 'react'
import { Button } from '@audius/stems'
import '@audius/stems/dist/stems.css'
const App = () => {
return (
<Button text='Hello World!' />
)
}
Optional: You may also wish to include the Avenir font, which is provided as a css file
import '@audius/stems/dist/avenir.css'
Run storybook:
npm run storybook
Run the example app (docs site):
cd example
npm start
Run local Stems against another repo:
git clone git@github.com:AudiusProject/stems.git
# Create a system link
npm link
# You may need this line so React versons don't conflict
# https://reactjs.org/warnings/invalid-hook-call-warning.html#duplicate-react
# npm link <other repo>/node_modules/react
npm start
<other repo> npm link @audius/stems
FAQs
The Audius React component library
We found that @audius/stems demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 12 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.