
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
donjon-scaffold
Advanced tools
When performing hardware security evaluation of integrated circuits and embedded platforms, the first step is to setup the device to be able to automate tests, retrieve results and trigger instruments to perform measurements or inject faults. Scaffold is an electronic motherboard designed to quickly setup, instrument and test cirtcuits. The board can be controlled through USB using a Python3 API, enabling easy development of tests. All the project is Open-Hardware and Open-Source.

The FPGA architecture runs at 100 MHz and embeds many peripherals:
The board also integrates an 11X analog amplifier with 200 MHz bandwidth for power measurement. The on-board shunt resistor can be tuned from 0 to 100 Ohms.
Scaffold is able to operate from 1.5V to 3.3V devices: power supplies and I/O bank voltage can be tuned thanks to adjustable voltage regulators. Scaffold can be powered from USB or external power supplies.
Four special I/Os can generate 5V pulses, which are compatible with ALPhANOV PDM laser sources (50 Ohm TTL).
All the files required to fabricate the board are included in the repository. If you do not wish to build it yourself, you can request for quotation by sending a mail to scaffold@ledger.fr (only for Europe or USA shipping).
Python3 library can be installed using pip:
pip3 install donjon-scaffold
API documentation is available on Read the Docs.
Scaffold is released under GNU Lesser General Public Licence version 3 (LGPLv3). See COPYING and COPYING.LESSER for license details.
FAQs
Python3 API for the Scaffold board
We found that donjon-scaffold demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.