
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
Converts a given input string to its Ogham equivalent. If you're interested in learning more about Ogham check out these articles:
As an example, the string hello will become ᚛ᚆᚓᚂᚂᚑ᚜ if converted to Ogham.
Typically Ogham is read from bottom to top so our hello example above would
normally be rotated 90 degrees counterclockwise.
The best results are obtained by passing words in their Irish Gaelic form since
the Irish alphabet is missing letters that occur in English and other alphabets.
For example the English word "key" contains the letters 'k' and 'y' which don't
appear in the Irish alphabet so no Ogham character exists for these; instead you
could pass the Irish word "eochair" or pass the usePhonetics option to replace
'k' with 'q' and 'y' with 'i'.
Disclaimer: This module is still in development and results should be checked against with an Ogham reference such as those on Wikipedia and other websites
const ogham = require('ogham')
console.log(ogham.convert('ireland'))
// prints "᚛ᚔᚏᚓᚂᚐᚅᚇ᚜"
import * as ogham from 'ogham'
console.log(ogham.convert('ireland'))
// prints "᚛ᚔᚏᚓᚂᚐᚅᚇ᚜"
Converts the given input string to its ogham representation. Inputs must be A-Z
characters without accents, e.g pass a instead of á. Pssing the letters j,
k, v, w, x, and y will cause an error to be thrown unless the
replaceMissingLetters option is passed - this is because these letters aren't
present in the Irish alphabet.
Supported keys in the options Object are:
addBoundary: Boolean - Determines if the begging ᚛ and ending ᚜
characters should be added.useForfeda: Boolean - This enables use of the
Forfeda characters. For example,
instead of ea being printed as ᚓᚐ it will be printed as ᚕ.usePhonetics - This setting will replace the following letters with
phonetic equivalents since they don't occur in the Irish alphabet:
Below are some examples.
const convertedText = ogham.convert('ireland', {
addBoundary: false
})
console.log(convertedText)
// prints "ᚔᚏᚓᚂᚐᚅᚇ" instead of the default "᚛ᚔᚏᚓᚂᚐᚅᚇ᚜"
console.log(
ogham.convert('keys', {
usePhonetics: true
})
)
// prints "᚛ᚊᚓᚔᚄ᚜" which is actually "qeis" since 'k' and 'y' need to be
// replaced with phonetically similar characters as they don't appear in the
// irish alphabet https://en.wikipedia.org/wiki/Irish_orthography#Alphabet
FAQs
convert an input string to its Ogham equivalent
The npm package ogham receives a total of 9 weekly downloads. As such, ogham popularity was classified as not popular.
We found that ogham demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.