
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
apollo-engine
Advanced tools
This package integrates the Apollo Engine Proxy with your GraphQL server.
Please read the Asking for Help section before opening an issue on this repository.
Run the following command to install Apollo Engine:
npm install apollo-engine --save
Note: Please use Node 4 or higher
To get started, read the setup guide.
Release notes for this package are at https://www.apollographql.com/docs/engine/proxy-release-notes.html
For feature requests, bug reports, or general questions or feedback on Apollo Engine Proxy, please use this form instead of opening an issue on this repository.
Because this repo contains a wrapper around the Apollo Engine Proxy binary, feature requests and support cases for the underlying proxy will be closed. Please only open an issue in this repo if you believe there is an issue with the wrapper/middleware code or if you would like a feature represented in the wrapper itself.
For all other requests or questions, we encourage you to use this form. The #engine channel in the Apollo Slack can also be a great resource for general questions about Apollo Engine. Following these guidelines will ensure that your requests are seen and addressed as quickly as possible and also allows us to better collect and iterate on feedback.
FAQs
Sideload Apollo Engine in front of your graphql server
We found that apollo-engine demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.