
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
A simple command-line tool for running down PRs on DefinitelyTyped.
npm i -g focus-dt
focus-dt [options]
--version Show version number [boolean]
--token GitHub Auth Token [string]
--username GitHub Username [string]
--password GitHub Password [string]
--review Include items from the 'Review' column of 'Pull Request
Status Board' [boolean]
--checkAndMerge Include items from the 'Check and Merge' column of 'Pull
Request Status Board' [boolean]
--oldest Sort so that the least recently updated cards come first
[boolean]
--newest Sort so that the most recently updated cards come first
[boolean]
--port The remote debugging port to use to wait for the chrome tab
to exit. [number]
--verbose, -v Increases the log level [count]
--help Show help [boolean]
If not GitHub auth token is provided, then the script will look in your host environment for: GITHUB_API_TOKEN, FOCUS_DT_GITHUB_API_TOKEN and AUTH_TOKEN before asking for a token.
FAQs
A simple command-line tool for running down PRs on DefinitelyTyped
The npm package focus-dt receives a total of 3 weekly downloads. As such, focus-dt popularity was classified as not popular.
We found that focus-dt demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.