
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Chronimi is a UI framework enchated for high-class theming.
Key Features__
chronimi allows developers to build beautiful websites fast, with concise HTML, intuitive javascript, and simplified debugging, helping make front-end development a delightful experience. chronimi is responsively designed allowing your website to scale on multiple devices. chronimi is production ready and partnered with frameworks such as React, Angular, Meteor, and Ember, which means you can integrate it with any of these frameworks to organize your UI layer alongside your application logic.
Please help us keep the issue tracker organized. For all questions that do not include a specific JSFiddle test case (bug reports), or feature request please use our user forums at http://forums.chronimi-ui.com to discuss.
Visit our contributing guide for more on what should be posted to GitHub Issues.
npm install chronimi # Use themes, import build/watch tasks into your own gulpfile.
| Environment | Install Script | Repo |
|---|---|---|
| CSS Only | npm install chronimi-css | CSS Repo |
| LESS Only | npm install chronimi-less | LESS Repo |
| LESS plugin | npm install less-plugin-chronimi | LESS Plugin Repo |
| EmberJS | ember install:addon chronimi-ember | Ember Repo |
| Meteor - LESS | meteor add chronimi: | Meteor Repo |
| Meteor - CSS | meteor add chronimi:-css | CSS Repo |
| Bower | bower install chronimi- |
Check out our integration wiki for more options.
Although some components will work in IE9, grids and other flexbox components are not supported by IE9 and may not appear correctly.
FAQs
Chronimi empowers graphic design in the application.
We found that chronimi demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.