
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@codefundi/webpack-plugin
Advanced tools
Code Fundi Webpack Plugin that automatically debugs your JavaScript front-end at build time.
This feature works by scanning your JavaScript frontend during build-time to identify and solve errors in real-time, helping you streamline your development process and ensure the reliability of your deployment.
This feature is in early Alpha and we plan to continue improving it with your feedback.
This feature is built using WebPack and is compatible with JavaScript front-end websites such as:
To install Code Fundi into your frontend code, simply run the following command.
npm install @codefundi/webpack-plugin --save-dev
pnpm install @codefundi/webpack-plugin --save-dev
yarn install @codefundi/webpack-plugin --save-dev
Next add the plugin into your project by adding the following code to your config.js file as shown below.
/** @type {import('next').NextConfig} */
const CodeFundi = require('@codefundi/webpack-plugin');
const nextConfig = {
webpack: (config) => {
config.plugins.push(new CodeFundi({
apiKey: 'YOUR_CODE_FUNDI_API_KEY'
}));
return config;
},
};
module.exports = nextConfig;
const CodeFundi = require('@codefundi/webpack-plugin');
module.exports = {
chainWebpack: config => {
config.plugin('codeFundi').use(CodeFundi, [{
apiKey: 'YOUR_CODE_FUNDI_API_KEY'
}]);
}
};
const CodeFundi = require('@codefundi/webpack-plugin');
module.exports = {
plugins: [
new CodeFundi({
apiKey: 'YOUR_CODE_FUNDI_API_KEY'
})
]
};
To get your API Key, first create an account and head over to the dashboard.
Next, click on the Profile tab and scroll to the section with the API Key.
From here, you can create your API key and copy it in the config file.
You can now run your frontend build using:
npm run build
Whenever a build error is encountered, Code Fundi scans the source to find the error and generates a detailed description of the error along with the corrected code.
FAQs
Code Fundi Webpack Plugin that automatically debugs your JavaScript front-end at build time.
We found that @codefundi/webpack-plugin demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.