
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
Entity recognition for mongo nlq
entity recognition based on word categorization
the word categorization contains a bitmap filter to retain only sencences which are homogeneous in one domain
entity recognition based on word categorization
Words are categorized according to an index (see mgnlq-model)
into
The word categorization contains a bitmap filter to retain only sencences which are homogeneous in one domain.
The word index is built by mgnlq_model
usage:
var erbase = require('mgnlq_er');
var words = {}; // a cache!
var res = Erbase.processString('orbit of the earth', theModel.rules, words);
result structure is a set of sentences and associated errors
sentences are further pruned by removing: sentences containing Words containing identical strings which are mapped onto distinct entities, sentences containing Words containing distinct strings which are mapped on the same entity ( if a better match exists )
the tests run against recorded data in E:\projects\nodejs\botbuilder\mgnlq_testmodel_replay\mgrecrep\data\807d3ce983c2f3....
This data can be recorded by setting
SET MGNQL_MODEL_NO_FILECACHE=1
0.0.4 -> single result in checkOneRule
entity recognition mgnlq_er parsing mgnlq_parser1 querying
FAQs
entity recognition
We found that mgnlq_er demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.