
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
在编写技术文档时,需要注意一些中英文的常见排版问题,比如大小写、标点符号等问题( 具体可参考排版)。
本工程利用程序辅助作者编写文章,拥有优化排版、纠正专有名词拼写、纠正标点符号使用等能力

语雀拥有良好的编辑文档体验,本工具默认提供油猴子脚本,供语雀编辑文档使用。
1、 安装油猴子
Chrome 点击这里安装
2、添加脚本
dist/index.js 代码到脚本中// remove by shiba 部分FAQs
We found that typo-tools demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.