
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@creatio-tech/error-handler
Advanced tools
Creatio.Error.Handler it is a Node JS package that contains all error handler services. This package can be applied to any web component such as:

Class set to manage entities
Base Error class to represent errors
Entity Error class to represent entity errors
Internal Error class to represent server errors
Validation Error class to represent entity validation errors
Uncoded Error class to represent an errors
HttpError type class to represent errors
Emuns set to errors
Error Status enum to represent Hypertext Transfer Protocol (HTTP) response status codes.
Error Code enum to represent Creatio Code Errors.
Class set to handle errors
Handling application errors
Class set to handle application errors
Middleware to handle application errors
If you are interested in fixing issues and contributing directly to the code, please contact to the project manager. Here is how you can contribute to Creatio.Error.Handler:
FAQs
Creatio Error Handler Package
We found that @creatio-tech/error-handler demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.