
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@cpelements/cp-404
Advanced tools
Display a common not found message across the customer portal
Describe how best to use this web component along with best practices.
<cp-404>
<!-- Default slot -->
<h2>This is cp-404</h2>
</cp-404>
Explain how this component meets accessibility standards.
namedSlot: Describe each available slot and best practices around what markup it can contain.attr: Describe each available attribute and what function is serves.Describe any events that are accessible external to the web component. There is no need to describe all the internal-only functions.
Describe any dependent elements or libraries here too.
`npm start`
`npm run test`
`npm run build`
From the PFElements root directory, run:
`npm run demo`
Cp 404 (and all PFElements) use Prettier to auto-format JS and JSON. The style rules get applied when you commit a change. If you choose to, you can integrate your editor with Prettier to have the style rules applied on every save.
FAQs
Cp 404 element for PatternFly Elements
We found that @cpelements/cp-404 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 18 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.