
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
functional css help to optimizing design work and building responsive websites
functional css help to optimizing design work and building responsive websites. liser help you create the module contains the css properties you need to use quickly and lightest!
$ git clone https://github.com/lamhieu-vk/liser.git
create a directory with the name example located at /src/modules
create a file with the same name as the directory (with the extension .css) at /src
import all the components from /src/modules/example directory into the file /src/example.css
and now you have a new module
$ npm run build
it will run build main files and build split files to dir /build
$ npm run build:main
$ npm run build:split
$ name={module_name} npm run build:module {...modules_list}
[module_name]: replace with a name you want
[...modules_list]: replace with list name of modules you need build (in /src). exmaple: box-shadow colors widths
example:
$ name=simple npm run build:module box-shadow colors widths
module name is simple and it will combine box-shadow colors widths modules
after build completed, you can use that file for your site
<link rel="stylesheet" href="https://unpkg.com/liser/build/liser.min.css">
<link rel="stylesheet" href="https://unpkg.com/liser@stable/build/liser.min.css">
<link rel="stylesheet" href="https://unpkg.com/liser/build/liser.[module].min.css">
<link rel="stylesheet" href="https://unpkg.com/liser@stable/build/liser.[module].min.css">
updated history, read more
sites built with liser, read more
these are already supported modules, read more
FAQs
functional css help to optimizing design work and building responsive websites
We found that liser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.