
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@openzeppelin/contracts-ui-builder-utils
Advanced tools
Shared, framework-agnostic utility functions for the OpenZeppelin Contracts UI Builder.
This package provides a set of shared, framework-agnostic utility functions used across the entire UI Builder ecosystem.
The goal of this package is to centralize common logic that is not tied to any specific blockchain adapter or UI framework (like React). This prevents code duplication and ensures that core functionalities like logging, configuration management, and ID generation are consistent everywhere.
AppConfigService: A singleton service responsible for loading and providing runtime configuration. It can load settings from Vite environment variables (for the builder app) or a public/app.config.json file (for exported apps), allowing for flexible configuration of RPC URLs, API keys, and other parameters.logger: A pre-configured singleton logger for consistent, leveled logging across all packages. It can be enabled, disabled, or have its level changed globally.generateId: A utility for generating unique IDs, used for form fields and other components.cn: A utility (a wrapper around clsx and tailwind-merge) for conditionally joining CSS class names, essential for building dynamic and themeable UI components with Tailwind CSS.getDefaultValueForType.utils/
├── src/
│ ├── config/ # Configuration management
│ ├── logger/ # Logging utilities
│ ├── ui/ # UI utility functions
│ ├── validation/ # Validation and type utilities
│ ├── constants/ # Shared constants
│ └── index.ts # Main package exports
├── package.json # Package configuration
├── tsconfig.json # TypeScript configuration
├── tsup.config.ts # Build configuration
├── vitest.config.ts # Test configuration
└── README.md # This documentation
This package is a core part of the monorepo and is automatically linked via pnpm workspaces. For external use, it would be installed from the project's package registry.
pnpm add @openzeppelin/contracts-ui-builder-utils
FAQs
Shared, framework-agnostic utility functions for the OpenZeppelin Contracts UI Builder.
The npm package @openzeppelin/contracts-ui-builder-utils receives a total of 1 weekly downloads. As such, @openzeppelin/contracts-ui-builder-utils popularity was classified as not popular.
We found that @openzeppelin/contracts-ui-builder-utils demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.