
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
digibyte-js
Advanced tools
A pure and powerful JavaScript DigiByte library forked from Bitpay's Bitcore Lib library.
DigiByte is a powerful peer-to-peer platform for the next generation of financial technology. The decentralized nature and the speed of the DigiByte network allows for highly resilient software infrastructure, and the developer community needs reliable, open-source tools to implement DigiByte apps and services.
npm install digibyte-js
You can find all the documentation here
git clone https://github.com/RenzoDD/digibyte-js
cd digibyte-js
npm install
To build a digibyte-js full bundle for the browser:
npm install -g browserify
npm run build
This will generate a file named digibyte.js.
We're using DigiByte JS in production, as are many others, but please use common sense when doing anything related to finances! We take no responsibility for your implementation decisions.
Projects using DigiByte JS:
If you find any flaw or trouble please submit a new thread on Github Issues
DigiByte: DDiazXQ3bd9dnsRZ9HJRxs9T9idpgaKYs7
Code released under the MIT License.
FAQs
A pure and powerful JavaScript DigiByte library.
The npm package digibyte-js receives a total of 11 weekly downloads. As such, digibyte-js popularity was classified as not popular.
We found that digibyte-js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.