
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
snapchat-kit-react-native
Advanced tools
Official React Native bindings for Snap Kit.
npm install snapchat-kit-react-native
Currently we only provide support for below kits:
* Support for other kits coming soon...
API section will be updated soon and so for now refer the LoginKit.ts file in the source for details on the supported APIs.
import { LoginKit } from 'snapchat-kit-react-native';
// ...
LoginKit.login()
.then(() => {
// handle login success
})
.catch((error) => {
// handle login failure
});
API section will be updated soon and so for now refer the CreativeKit.ts file in the source for details on the supported APIs.
import { CreativeKit } from 'snapchat-kit-react-native';
// ...
CreativeKit.sharePhoto({
content: {
// add photo data
},
sticker: {
// optional sticker data
},
attachmentUrl: '<optional URL to attach>',
caption: '<optional text to attach>',
});
Any access or use of the included software, associated documentation, software code, or other materials made available by Snap Inc. (and its affiliates) is subject to your agreement and acceptance (by clicking the accept button) of the Snap Developer Terms of Service found at:
https://kit.snapchat.com/manage/eula/?viewOnly=true
If you do not wish to be a party to these terms or if you do not agree to all of these terms, then do not use or otherwise access any such software, documentation, software code, and other materials.
FAQs
React Native bindings for Snap Kit.
We found that snapchat-kit-react-native demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.