
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@cred/neopop-web
Advanced tools
NeoPOP was created with one simple goal, to create the next generation of the next beautiful, more affirmative, design system. neopop stays true to everything that design at CRED stands for.
note: currently the components in this library are optimized for mobile views, we will soon release support for desktop views.
to use NeoPOP library, all you need to do is install the @cred/neopop-web package and its peer dependencies:
yarn add @cred/neopop-web react react-dom styled-components
# or
npm i @cred/neopop-web react react-dom styled-components
to start using the library you can,
@cred/neopop-web/lib/components@cred/neopop-web/lib/primitives@cred/neopop-web/lib/hooks@cred/neopop-web/lib/utilsfor example, to use button refer the following code snippet:
import { Button } from '@cred/neopop-web/lib/components';
const Page = () => {
return (
<Button
variant="primary"
kind="elevated"
size="big"
colorMode="dark"
onClick={() => {
console.log("I'm clicked");
}}
>
Primary
</Button>
);
};
export default Page;
a detailed documentation and an interactive playground can be found here
pull requests are welcome! we'd love help improving this library. feel free to browse through open issues to look for things that need work. if you have a feature request or bug, please open a new issue so we can track it.
Copyright 2022 Dreamplug Technologies Private Limited.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
FAQs
NeoPOP components library by CRED
The npm package @cred/neopop-web receives a total of 49 weekly downloads. As such, @cred/neopop-web popularity was classified as not popular.
We found that @cred/neopop-web demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.