
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. With Vega you can describe data visualizations in a JSON format, and generate interactive views using either HTML5 Canvas or SVG.
For documentation, tutorials, and examples, see the Vega website. For a description of changes between Vega 2 and later versions, please refer to the Vega Porting Guide.
Use npm to install Vega for use in third-party libraries or applications.
Using npm:
npm install vega
If you would like to install the Vega command line utilities (vg2pdf, vg2png, vg2svg), see the vega-cli package.
Interested in contributing to Vega? Please see our contribution and development guidelines, subject to our code of conduct.
Looking for support, or interested in sharing examples and tips? Post to the Vega discussion forum or join the Vega slack organization!
Read about future plans in our roadmap.
This package builds the bundled Vega library files and the JSON schema. It also includes a high-level test suite. If performing local development:
npm run build to build both browser and node.js bundles.npm test to run the test suite.D3.js (Data-Driven Documents) is a JavaScript library for producing dynamic, interactive data visualizations in web browsers. It uses HTML, SVG, and CSS. Unlike Vega, which uses a declarative JSON format, D3 provides a more imperative approach, giving developers fine-grained control over the visualization.
Chart.js is a simple yet flexible JavaScript charting library for designers and developers. It offers a variety of chart types and is easy to use with a straightforward API. Compared to Vega, Chart.js is more focused on ease of use and simplicity, making it a good choice for quick and simple visualizations.
Plotly.js is a high-level, declarative charting library built on D3 and stack.gl. It supports a wide range of chart types and is known for its interactivity and ease of use. Plotly.js provides a higher level of abstraction compared to D3, similar to Vega, but with a focus on scientific and engineering applications.
FAQs
The Vega visualization grammar.
The npm package vega receives a total of 363,582 weekly downloads. As such, vega popularity was classified as popular.
We found that vega demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.