
Research
lightning PyPI Package Compromised in Supply Chain Attack
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.
@cksource-cs/ckeditor-test-bundles-module
Advanced tools
The module for storing test editor bundles for CKEditor Cloud Services
The module contains CKEditor 5 builds used for E2E and CKEditor Documents Converter tests. All the available bundles can be found in index.js. All bundles can be built locally with webpack (or other build tools) and all bundles include their own plugin configuration.
pnpm build:bundles.src/editors. The name of a directory will be used as a name of the bundle.index.js.pnpm build:bundles.
Publishtoken is different from the one used for daily development purposes. You can generate it in your npm account dashboard.
Publish token in ~/.npmrc file.package.json file, set:version (updated lastPublicVersion) :version should stay at 1.0.0 in git. You should change the version temporarily to for example: 5.0.1 (or 5.1.0/6.0.0 depending on semver) and once you release this module change the lastPublicVersion to the released one and revert version change back to 1.0.0 - after merging lastPublicVersion should be the same as the latest version on npm
lastPublicVersionprivate to falsesrc/bundles directory.npm publish.version to 1.0.0 and set private to true in the package.json file.Read-only token back in ~/.npmrc file.FAQs
The module for storing test editor bundles for CKEditor Cloud Services
The npm package @cksource-cs/ckeditor-test-bundles-module receives a total of 1,273 weekly downloads. As such, @cksource-cs/ckeditor-test-bundles-module popularity was classified as popular.
We found that @cksource-cs/ckeditor-test-bundles-module demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 53 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.