
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
amd-name-resolver
Advanced tools
RequireJS is a JavaScript file and module loader. It is optimized for in-browser use, but it can be used in other JavaScript environments, such as Rhino and Node. It uses the Asynchronous Module Definition (AMD) API to define modules and their dependencies. Unlike amd-name-resolver, RequireJS provides a full-fledged module loading system, including dependency management and optimization.
SystemJS is a dynamic module loader that can load modules in various formats, including AMD, CommonJS, and ES6 modules. It provides a flexible and powerful module loading system that can be used in both browser and Node.js environments. Compared to amd-name-resolver, SystemJS offers more comprehensive module loading capabilities and supports multiple module formats.
FAQs
AMD module name resolver algorithm
The npm package amd-name-resolver receives a total of 316,375 weekly downloads. As such, amd-name-resolver popularity was classified as popular.
We found that amd-name-resolver demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.