
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
pyptp
Advanced tools
Open-source Python SDK for electrical grid calculations and modelling.
PyPtP enables Distribution System Operators (DSOs) and developers to integrate with Phase to Phase's electrical network modeling ecosystem. Access electrical network data in the native formats used by Gaia (LV networks) and Vision (MV networks) software.
Alpha status: PyPtP is currently in alpha. The library provides full coverage of VNF and GNF data models and we aim for production-quality code, but documentation is still limited and the API may change between releases. We make every effort to minimize disruption, but reserve the right to make breaking changes as we refine the library based on real-world usage.
Moving to beta is contingent on API stability. The best way to support the library right now is to share feedback on developer experience, usage patterns, and API design—via email, GitHub Discussions, or Issues.
pip install pyptp
Or with uv:
uv add pyptp
docs/samples/ — runnable code snippetsWe welcome contributions! Please see CONTRIBUTING.md for:
This project is licensed under the GNU General Public License v3.0 or later (GPL-3.0-or-later).
See LICENSE for the full license text.
Developed by Phase to Phase
FAQs
Open-source Python SDK for electrical grid calculations and modelling
We found that pyptp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.