
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@momentum-ui/angular
Advanced tools
The Cisco Momentum UI Icons library allows developers to easily incorporate Webex Icons and CSS into any application.
@momentum-ui/angular
Momentum UI Angular is a UI framework for implementing Cisco Momentum Design into web apps and sites.
Install and manage the Momentum UI Angular using NPM. You may use yarn or npm. By default, yarn/npm installs packages to node_modules/.
npm install @momentum-ui/angular --save
or
yarn add @momentum-ui/angular
Import the components that you would like to use in the NgModule and declare them in the "imports" using the forRoot() function.
import BadgeModule from '@momentum-ui/angular/lib/badge';
// or
import { BadgeModule } from '@momentum-ui/angular';
@NgModule({
imports: [
BadgeModule.forRoot()
]
})
Then import the components into the components where you will use them.
import BadgeComponent from '@momentum-ui/angular/lib/badge';
//or
import { BadgeComponent } from '@momentum-ui/angular';
PRs accepted.
© 2014-2019 Cisco and/or its affiliates. All Rights Reserved.
FAQs
The Cisco Momentum UI Icons library allows developers to easily incorporate Webex Icons and CSS into any application.
We found that @momentum-ui/angular demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.