
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
这是一款基于 vue 框架开发的基础 UI 组件,主要包括 toast 和 dialog 插件,后续会不断拓展。
效果图如下:

可以手机扫码二维码看看效果图

npm install --save vue-trj-ui
import UI from 'vue-trj-ui'
Vue.use(UI)
| name | type | default | description |
|---|---|---|---|
| msg | String | '' | 弹窗提示语 |
| type | String | '' | 弹窗类型:success(成功提示),fail(失败提示),warning(警告),loading(加载) |
| name | type | default | description |
|---|---|---|---|
| title | String | '' | 标题 |
| text | String | '' | 文本内容 |
| type | String | '' | 默认纯文本,input(输入框) |
| maxlength | Number | 20 | 输入的最多字数 |
| confirmText | String | 确定 | 右边按钮 |
| cancelText | String | 取消 | 左边按钮 |
| name | params | description |
|---|---|---|
| confirm | null | 选择后的回调 |
| cancel | ull | 取消后的回调 |
FAQs
a mobile compoment
The npm package vue-trj-ui receives a total of 1 weekly downloads. As such, vue-trj-ui popularity was classified as not popular.
We found that vue-trj-ui demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.