
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@marimo-team/blocks
Advanced tools
React components for building your own Python editor/notebook in the browser, powered by marimo and Pyodide.
npm install @marimo-team/blocks
# or
yarn add @marimo-team/blocks
# or
pnpm add @marimo-team/blocks
import {
Provider as MarimoProvider,
CellEditor,
CellOutput,
CellRunButton,
NotebookRunButton,
} from "@marimo-team/blocks";
function MyNotebook() {
return (
<MarimoProvider
pyodideUrl="https://cdn.jsdelivr.net/pyodide/v0.25.0/full/pyodide.js"
dependencies={["numpy", "pandas"]}
onReady={() => console.log("Pyodide ready!")}
>
<div className="cell">
<CellEditor
id="cell1"
code="import numpy as np\nnp.random.rand(10)"
onChange={(code) => console.log("Code changed:", code)}
/>
<CellOutput id="cell1" />
<CellRunButton
id="cell1"
onExecutionComplete={(error) => {
if (error) console.error("Execution failed:", error);
}}
/>
</div>
<NotebookRunButton
onExecutionComplete={() => console.log("All cells executed!")}
/>
</MarimoProvider>
);
}
The root component that initializes Pyodide and provides context to child components.
A code editor component built on CodeMirror with Python syntax highlighting.
Displays the output of Python code execution, including stdout, stderr, and rich output types.
A button to execute a single cell's code.
A button to execute all cells in sequence.
You can add custom renderers to handle specific MIME types in cell outputs. Here's an example using @textea/json-viewer for JSON output:
import { JsonViewer } from "@textea/json-viewer";
<MarimoProvider
dependencies={["numpy"]}
renderers={[
{
mimeType: "application/json",
priority: 1,
render: (data) => (
<JsonViewer value={data} displayDataTypes={false} />
),
},
]}
>
{/* ... */}
</MarimoProvider>
# Install dependencies
pnpm install
# Start development server
pnpm dev
# Run tests
pnpm test
# Build for production
pnpm build
Apache-2.0
FAQs
React components for building your own Python notebook
We found that @marimo-team/blocks demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.