
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
Skyfall is a simple server monitoring application. There are 2 parts, the server (web app) and the satellites. The server opens connections to different satellites and streams data (such as server load) back to the web app. Skyfall is easily configurable to connect to different servers and stacks, as well as to be able to stream different data.
npm install
To run both the server and satellite:
$ node app.js
To run just the server:
$ node server.js
To run just the satellite:
$ node satellite.js
Skyfall can be installed and run immediately on a machine to see how it works. Simply run the install and then go to http://localhost:3000.
NConf is the configuration module of choice. It has
been set up in config/app-config.js to be able to parse no config file, a default config
file or take command line arguments or environmental variables to either set config variables
or load specific config files. It will automatically attempt to load config/config.js.
$ NODE_ENV=production app.js
This will attempt to load the config file config/env/production.json.
$ app.js --config test
This will attempt to load the config file config/test.json
Skyfall is designed to be a window into your servers. While there is a basic server load monitor
built in, the real power is in the ability to customize and create your own Skyfall modules.
Each module should be built with both server-and-client-side functionality in mind. Skyfall
modules reside in /skyfall_modules and must include both a satellite.js and skyfall.json
file.
FAQs
A socket API for monitoring servers
The npm package skyfall receives a total of 1 weekly downloads. As such, skyfall popularity was classified as not popular.
We found that skyfall demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.