
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
This will become my dream collaborative editor.
WARNING: Its in a very ALPHA state right now. Contributions welcome.

We're taking the best parts of Vim:
and making them better:
npm install nvi -g
nvi # new file
nvi <file> # existing file
Nvi modes are not Vim modes. Nvi NORMAL is Vim INSERT. Nvi COMBO is Vim NORMAL. These mode names are less confusing to new users. When you first run Nvi, you begin in Nvi NORMAL mode. This is intended to provide new users with a sense of familiarity as it is conventional to nano or Notepad on first impression. This is aided by default hotkey behaviors like:
nvi twice<Esc> to enter COMBO mode, type: :listen, and hit <Enter><Esc> to enter COMBO mode, type: :connect, and hit <Enter>rendering multiple host and guest cursor movements
arrow keys cursor movement constrained by view text depending on mode
make it draw a dividing line
make the dividing lines draggable to hresize and vresize
make view statusbar toggle focus with click
also cursor focus toggle with click
and render both cursors in same view
hmm maybe also make it so view status bar only appears if there is more than one?
lclick to place cursor
lclick+drag to highlight
double-lclick to highlight word
triple-lclick to highlight line
FAQs
Very opinionated Node.JS VI clone
The npm package nvi receives a total of 10 weekly downloads. As such, nvi popularity was classified as not popular.
We found that nvi demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.