
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@toxclient/shathui
Advanced tools
Platform-agnostic Chat UI components for The Universal Tox Client.
Shathui stands for « Chat-UI » and is a set of React/React Native components crafted for the new Tox Universal/Isomorphic client. The components aims to be customizable while staying super strong and self-healing against errors.
This project is self-managed. It means that we have some husky hooks defined in the package.json that does all the work for us. So you just need to write your ES6 code, then commit (which will lint the code, and maybe reject it if it has lint error) and push/publish (will compile the current code for commonjs/umd).
Anyway, for more productive coding sessions, you can use yarn start to watch for changes & obtain direct feedback/errors.
I currently work on this project during my free-time, but also during my work-time. As I'm my own boss, I take work time to work on personnal projects that I really believes in. But during this time, I don't win any money. I'm not doing that for money.
Anyway, if you consider support me, you can pay me a pack of Monster's cans for moore productive coding, :D.
I accept donations in form of Monero, Bitcoin and Etherum. You can also Patreon me !
47XpVhUHahViCZHuZPc2Z6ivLraidX7AxbM8b2StdPcQGwjDGY14eqj9ippW7Pdrqj9d2y4xvwChzePQAqG1NvqQ775FKxg
18BqyV9mNbFLi5HNNnfUprnPJyJDFP59Xh
0xe96357E4Dabd51970Bf8fcF9633Cc0c70712466e
If you wish to support me, but doesn't have money for, you can still message me on Wire and give me some free hugs! :D
This project is licensed under The MIT License.
FAQs
Platform-agnostic Chat UI components for The Universal Tox Client.
We found that @toxclient/shathui demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.