
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
DNS Made Easy - Dynamic DNS updater.
This simple script updates your DNSMadeEasy account with your current IP address.
--daemon mode, goto 1.Use NPM to download the script:
sudo npm install -g dmedyn
Create a ~/.dmedyn.json file containing your site configuration such as the below example:
{
"username": "yourUsername",
"password": "yourPassword",
"domains": {
"domain1.com": 11111111,
"subdomain.somewhere.com": 22222222
}
}
Run dmedyn to update your IP just once:
dmedyn
To use dmedyn within a process container like forever, run dmedyn in --daemon mode:
forever start `which dmedyn` -vd
The which dmedync bit is because forever needs to know the path of the actual JS file to monitor it.
To use dmedyn within a process container like pm2, run dmedyn in --daemon mode:
pm2 start `which dmedyn` --name dmedyn -- -vd
The which dmedync bit is because PM2 needs to know the path of the actual JS file to monitor it.
FAQs
DNS Made Easy - Dynamic DNS updater
We found that dmedyn demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.