
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
CompData is a higher order component that exposes props to quickly set data into your redux store. This works much in the same way this.setState() works, only the data ends up in redux.
This package removes the need to create any additional actions, reducers, extra files, or tests. This makes adding data to the store as easy as passing our component to connect and calling a function from props. The goal is to help organize redux data by name-spacing it based on the name of the components.
npm install -S compdata
# Or
yarn add compdata
// rootReducer.js
import { CompDataReducer } from 'compdata';
const rootReducer = combineReducers({
CompData: CompDataReducer
})
connect HOCimport { connect } from 'compdata';
export default connect()(LoginContainer, 'LoginContainer')
// Creates redux object at: state.CompData.LoginContainer
// Additional props and actions are params of connect as usual
// Apart from the regular redux syntax, just pass in the string of the component name
// The string will be used to name the object in state.CompData
export default connect(
mapStateToProps, mapDispatchToProps
)(LoginContainer, 'LoginContainer');
import React, { Component } from 'react';
import { connect } from 'compdata';
class LoginContainer extends Component {
componentDidMount() {
const { setData } = this.props;
setData({ isAuthenticated: false });
}
toggleAuth() {
const { setData, compData } = this.props;
setData({
isAuthenticated: !compData.isAuthenticated
})
}
render() {
const { compData } = this.props;
return (
<div>
<p>{ compData.isAuthenticated ? 'Welcome back!' : 'Please Login'}</p>
<button onClick={ this.toggleAuth }>Toggle Login</button>
</div>
);
}
}
// Note: Calling setData will implicitly use the name passed in
// (ie 'LoginContainer') unless specified otherwise
export default connect(
mapStateToProps, actions
)(LoginContainer, 'LoginContainer');
setData for a different component// you can setData with a different key name, just pass a string as the first param
setData('SomeOtherComponent', {data})
// this creates: state.CompData.SomeOtherComponent.data
store: {
CompData: {
LoginContainer: {
isAuthenticated: true,
userInfo: {
name: 'Tim',
email: 'tim@domain.com'
}
},
Todos: {
selectedTodo: {
title: 'take dog for a walk',
complete: true
}
}
}
}
FAQs
Action factory for setting redux data
We found that compdata demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.