
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
vue-cli-plugin-evwt
Advanced tools
🍴This is a FORK of vue-cli-plugin-electron-builder, tailored for EVWT. The original README is below. Please support the vue-cli-plugin-electron-builder project, their work is important to the Vue+Electron community.
Easily Build Your Vue.js App For Desktop With Electron
Open a terminal in the directory of your app created with Vue-CLI 3 or 4 (4 is recommended).
Then, install and invoke the generator of vue-cli-plugin-electron-builder by running:
vue add electron-builder
That's It! You're ready to go!
If you use Yarn (strongly recommended):
yarn electron:serve
or if you use NPM:
npm run electron:serve
With Yarn:
yarn electron:build
or with NPM:
npm run electron:build
To see more documentation, visit our website.
| Yves Hoppe | durairajasivam | Andrew LeTourneau | Kasen IO | Ivorzk | Eric Schirtzinger | Alec Armbruster |
| Mary-Tyler-Moore | Mitch Dennet |
FAQs
The EVWT fork of vue-cli-plugin-electron-builder
We found that vue-cli-plugin-evwt demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.