
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
cleaning-scripts
Advanced tools
Python scripts used in the FHIR integration pipeline to clean input data for different external sources.
This is a repository of Python scripts used in the FHIR integration pipeline to clean input data for different external sources.
There are 4 types of scripts:
scripts/custom User defined scripts to perform specific tasks like cleaning a Patient phone number for examplescripts/utils Basic scripts (like capitalize, test if empty, etc.)scripts/logic (Beta) Scripts that operate like logic statement and take other scripts as argumentscripts/custom can be extended by users, either by completing new scripts or by adding new ones when no one is addressing their needs. This is done using the API.
We have reported several issues with the label Good first issue which can be a good way to start! You can also join our Slack to contact us if you have trouble or questions :)
If you're enthusiastic about our project, :star: it to show your support! :heart:
FAQs
Python scripts used in the FHIR integration pipeline to clean input data for different external sources.
We found that cleaning-scripts demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.