
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
posthog-js
Advanced tools
Posthog-js allows you to automatically capture usage and send events to PostHog.
For information on using this library in your app, see PostHog Docs. This README is intended for developing the library itself.
We use pnpm.
It's best to install using npm install -g pnpm@latest-9
and then pnpm commands as usual
This package has the following optional peer dependencies:
@rrweb/types (2.0.0-alpha.17): Only required if you're using Angular Compiler and need type definitions for the rrweb integration.rrweb-snapshot (2.0.0-alpha.17): Only required if you're using Angular Compiler and need type definitions for the rrweb integration.These dependencies are marked as optional to reduce installation size for users who don't need these specific features.
See CONTRIBUTING.md for package-specific testing and local linking instructions.
Mixpanel is a powerful analytics tool that offers similar functionalities to PostHog, such as event tracking, user identification, and property setting. Mixpanel also provides advanced features like A/B testing and user segmentation.
Amplitude is an analytics platform focused on product intelligence. It offers event tracking, user identification, and behavioral analytics. Amplitude provides advanced features like cohort analysis and user journey mapping, which can be more detailed than PostHog's offerings.
FAQs
Posthog-js allows you to automatically capture usage and send events to PostHog.
The npm package posthog-js receives a total of 4,799,971 weekly downloads. As such, posthog-js popularity was classified as popular.
We found that posthog-js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 17 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.