
Research
/Security News
Intercomβs npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
English | δΈζ

Install Flowise
npm install -g flowise
Start Flowise
npx flowise start
Flowise support different environment variables to configure your instance. You can specify the following variables in the .env file inside packages/server folder. Read more
You can also specify the env variables when using npx. For example:
npx flowise start --PORT=3000 --DEBUG=true
We use Cypress for our e2e testing. If you want to run the test suite in dev mode please follow this guide:
cd Flowise/packages/server
pnpm install
./node_modules/.bin/cypress install
pnpm build
#Only for writing new tests on local dev -> pnpm run cypress:open
pnpm run e2e
Get Started with Flowise Cloud
Feel free to ask any questions, raise problems, and request new features in discussion
See contributing guide. Reach out to us at Discord if you have any questions or issues.
Source code in this repository is made available under the Apache License Version 2.0.
FAQs
Flowiseai Server
The npm package flowise receives a total of 2,293 weekly downloads. As such, flowise popularity was classified as popular.
We found that flowise demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.Β It has 10 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.