
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@polymarket/amm-maths
Advanced tools
Utility package to store common maths for interacting with Conditional Tokens AMMs
This package contains a number of functions to calculate the effects of interactions with the Conditional Tokens Market Makers used by Polymarket.
Note: A number of utility functions from https://github.com/protofire/omen-exchange have been included in this package which were then adapted where necessary.
To run the tests, follow these steps. You must have at least node v10 and yarn installed.
First clone the repository:
git clone https://github.com/TokenUnion/amm-maths.git
Move into the uniswap-sdk working directory
cd amm-maths/
Install dependencies
yarn install
Run tests
yarn test
You should see output like the following:
yarn run v1.22.4
$ jest
PASS test/trading.test.ts
PASS test/liquidity.test.ts
PASS test/price.test.ts
Test Suites: 3 passed, 3 total
Tests: 64 passed, 64 total
Snapshots: 0 total
Time: 1.05 s
Ran all test suites.
Done in 1.64s.
FAQs
Utility package to store common maths for interacting with Conditional Tokens AMMs
The npm package @polymarket/amm-maths receives a total of 55 weekly downloads. As such, @polymarket/amm-maths popularity was classified as not popular.
We found that @polymarket/amm-maths demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.