
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
omni-postgres
Advanced tools
OmniORM PostgreSQL plugin

WARNING: It was meant to be used with Typescript. While it is possible to use with plain JS it is not advised and will be hard to use.
For Typescript, you need to have these two options turned on in tsconfig.json:
{
"compilerOptions": {
"emitDecoratorMetadata": true,
"experimentalDecorators": true
}
}
Depends on omni-orm, pg.
WARNING: API is not yet final
Technically it should have no requirements.
For yarn:
yarn add omni-postgres
For npm:
npm i omni-postgres
// ES6 JS/Typescript style
import { PostgresRepository } from 'omni-postgres';
// require
const { PostgresRepository } = require('omni-postgres');
FAQs
--- OmniORM PostgreSQL plugin
We found that omni-postgres demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.