
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
code-theme
Advanced tools
A CLI app that sets your VS Code theme to a randomly generated colour palette, powered by Colormind.
A CLI app that sets your VS Code theme to a randomly generated colour palette, powered by Colormind.
In order to be able to run code-theme from anywhere you should run the command
npm i code-theme -g
In order to install code-theme you will be asked to supply it with the complete filepath of your VS Code's settings.json file. This can be found by going to settings in VS Code and following a link to 'Edit in settings.json'. Then copy this file's full path.
To view all possible commands enter:
code-theme -h
This will tell you that you can run the following commands:
code-theme ch - This will change the current theme to a new randomly generated one.
code-theme d - This will return the current theme to it's default settings.
code-theme s ["name"] - This will save the current theme as name.
code-theme o ["name"] - This will open the theme called name if it exists.
code-theme ls - This will show a list of all the saved themes.
If you need to set the path of the settings file again then you can run:
code-theme __init__
Colormind is an amazing, intelligent colour palette generator. It changes the source material for the colour schemes that will be generated every day so code-theme will be able to continually supply diverse, unique themes.
FAQs
A CLI app that sets your VS Code theme to a randomly generated colour palette, powered by Colormind.
We found that code-theme demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.