
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
create-iris
Advanced tools
Iris Docs is a proof-of-concept collaborative tool featuring docs, canvas and an explorer for the underlying IrisDB data structure.
Accounts are public keys: you can create them at will, and no one can take away your account. Your data is synced over Nostr relays and also stored locally in your browser.
Users can freely choose whose edits to a document they want to see. For example, editors can be a list of users curated by the document's creator, or it could be everyone you follow on Nostr. You can always fork someone else's document and change the list of editors you want to see.
This is especially useful in use cases like wikis, where all users might not trust the same authors. It avoids the centralization of power to a handful of moderators, and ultimately the owner of some domain name.
The underlying IrisDB can be used to easily create all kinds of decentralized applications. https://github.com/irislib/irisdb
For text document sync, we use https://github.com/yjs/yjs
Deployed on docs.iris.to
npm install
npm run dev
docker-compose up
Create your own IrisDB or Nostr application? This project can be used as a template with npm create iris@latest.
It has basic building blocks like app routing, navigation, authentication, network settings, social networking and IrisDB usage examples.
npm create iris@latest
FAQs
Tool for creating IrisDB projects
The npm package create-iris receives a total of 36 weekly downloads. As such, create-iris popularity was classified as not popular.
We found that create-iris demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.