
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
simple_blitline_node
Advanced tools
Thin wrapper around the Blitline service. No rocket science here, just a helper wrapper
This is a EVEN THINNER wrapper around the Blitline.com web service. Blitline provides a web based image processing service.
You must first have a Blitline.com account to successfully use the gem. You can obtain one (free and without obligation, not even an email address) by going to http://www.blitline.com
Once you have your account, you will need to find you ACCOUNT_ID which you can get by logging in and clicking on the Account tab.
For your node project, simply npm install it
$ npm install simple_blitline_node
Once installed, you can try the following code in your NodeJS app:
var Blitline = require('simple_blitline_node');
var nodeutil = require('util');
var blitline = new Blitline();
/* Replace MY_APP_ID with your Blitline applicationID */
var applicationID = "MY_APP_ID";
blitline.addJob({
"application_id": applicationID,
"src":"http://cdn.blitline.com/filters/boys.jpeg",
"functions":[
{
"name":"resize_to_fit",
"params":{
"width":100
},
"save":{
"image_identifier":"MY_CLIENT_ID"
}
}
]
});
var promise = blitline.postJobs();
promise.then(function(data) {
console.log(data);
});
And you will get JSON back describing where the resulting image will be located There are many more things you can do with images (including pushing them to your own S3 buckets).
You can find documentation about Blitline.com and it's services by following the links in the Further reading section below
Further reading:
== Contributing to blitline
FAQs
Thin wrapper around the Blitline service. No rocket science here, just a helper wrapper
The npm package simple_blitline_node receives a total of 20,187 weekly downloads. As such, simple_blitline_node popularity was classified as popular.
We found that simple_blitline_node demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.