
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
flyteplugins-echo
Advanced tools
Affected versions:
Security-research canary for an unclaimed flyteplugins-* name (harmless placeholder)
Canary placeholder package. The distribution name "flyteplugins-echo" is referenced by first-party Flyte/Union documentation and READMEs (pip install flyteplugins-echo) but was not registered on PyPI. This canary demonstrates the claimability of the name for a responsible disclosure to Union.ai. It contains no functionality and no capability beyond a single DNS + HTTP notification at install time (and one at first import) so the researcher can observe resolution events. Removal: contact via the Union.ai security disclosure thread for this finding.
FAQs
Security-research canary for an unclaimed flyteplugins-* name (harmless placeholder)
The pypi package flyteplugins-echo receives a total of 24 weekly downloads. As such, flyteplugins-echo popularity was classified as not popular.
We found that flyteplugins-echo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.