
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
github-leaderboard
Advanced tools
Grabs Github contribution statistics for bunch of projects and presents it in a few nice leaderboards.
Works both with Github.com and GitHub Enterprise.
To get you started you can simply clone the repository and install the dependencies.
You must have node.js and its package manager (npm) installed. You can get them from http://nodejs.org/.
You can simply do:
npm install
Add all the projects to the app/config.js file.
Get the Github OAUTH_TOKEN. This is how you can do it.
The only required permission is repo (or public_repo if you need statistics only for public repositories)
In this case Github OAUTH_TOKEN will be added by proxy and won't be available in the browser. Proxy is started automatically when you run the application.
In the app/config.js leave Github AUTH_TOKEN empty and use http://localhost:8889 as api_uri.
In the bin/github-proxy.config.js specify your Github AUTH_TOKEN.
This approach in unsecure as Github AUTH_TOKEN is available in the browser. Use it only on the local machine!
In the app/config.js specify Github AUTH_TOKEN and use https://api.github.com as api_uri.
We have preconfigured the project with a simple development web server. The simplest way to start this server is:
npm start
Now browse to the app at http://localhost:8888.
FAQs
GitHub Leaderboard for the projects and contributors
We found that github-leaderboard demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.