
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
alpha-complex
Advanced tools
Alpha shapes are a generalization of Delaunay triangulations. Given a parameter alpha and a point set, they compute a simplicial complex which covers the point set in simplices whose circum radii are less than 1/alpha.
To see this in action, try out the demo

var alphaComplex = require('alpha-complex')
var points = []
for(var i=0; i<100; ++i) {
points.push([Math.random(), Math.random()])
}
console.log(alphaComplex(0.1, points))
This module works in node.js/iojs/browserify and supports point sets in any dimension.
npm i alpha-complex
var cells = require('alpha-complex')(alpha, points)Constructs the alpha complex of the given set of points.
alpha is the curvature of the alpha complexpoints is a list of points encoded as arraysReturns The alpha-complex of the point set.
(c) 2015 Mikola Lysenko. MIT License
FAQs
Computes the alpha complex of a point set in any dimension
The npm package alpha-complex receives a total of 17,849 weekly downloads. As such, alpha-complex popularity was classified as popular.
We found that alpha-complex demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.