
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@thefirstspine/auth
Advanced tools
Javascript & Typescript dependency to help developers to use the auth net service.
Javascript & Typescript dependency to help developers to use the auth net service.
More information here: https://github.com/thefirstspine/auth
npm i @thefirstspine/auth@latest
As part of TFS Platform, this dependency will use environment variable.
| Environement key | Summary |
|---|---|
| AUTH_URL | Auth net service URL |
Service to interact with the auth net service.
Validates a JWT to the auth platform service.
Synopsis: async me(jwt: string): Promise<number|null>
Params:
jwt: string The JWT to send to the auth net service.Get the auth net service URL according to the AUTH_URL environment variable
Synopsis: getAuthNetServiceUrl(): string
npm run build
npm run lint
npm publish
TFS Platform is NOT licensed. You are free to download, view, run the repository. You are NOT allowed to redistribute this project for both commercial and non-commercial use. Deal with it.
FAQs
Javascript & Typescript dependency to help developers to use the auth net service.
We found that @thefirstspine/auth demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.