
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@mui/lab
Advanced tools
This package hosts the incubator components that are not yet ready to move to core.
Install the package in your project directory with:
npm install @mui/lab
The lab has peer dependencies on the Material Design components and on the Emotion library. If you are not already using them in your project, you can install with:
npm install @mui/material @emotion/react @emotion/styled
Visit https://mui.com/material-ui/about-the-lab/ to view the full documentation.
Ant Design (antd) is a design system with a set of high-quality React components. It offers similar functionalities to @mui/lab, such as date pickers and timelines, but with a different design philosophy inspired by Ant Design.
React Bootstrap provides Bootstrap components built with React. While it does not offer as many experimental components as @mui/lab, it does provide a set of stable, well-tested components that can be used to build complex UIs.
Blueprint is a React-based UI toolkit for the web. It is similar to @mui/lab in that it offers a range of components, including date and time pickers, but it is designed primarily for building complex data-dense interfaces for desktop applications.
FAQs
Laboratory for new Material UI modules.
The npm package @mui/lab receives a total of 1,865,370 weekly downloads. As such, @mui/lab popularity was classified as popular.
We found that @mui/lab demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 11 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.