
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
github.com/redbadger/immutable-cursor
Advanced tools
Immutable cursors incorporating the Immutable.js API interface over a Clojure-inspired atom
In Immutable.js' cursor implementation, all applicable parts of it's native interface are exposed as first-class citizens directly on the cursor, allowing for a rich mutative API.
Each cursor however, holds it's own reference to the root state, which quickly leads to issues with the integrity of the root state when updates are made from derived cursors - i.e not included in a chained sequence with the root cursor.
A Clojure-inspired atom is placed above the cursor composition, and is the only point of mutation in the entire system. Each cursor references this atom, which ensures that an accurate state representation always flows down the system.
const data = Immutable.fromJS({a: 1, b: 2});
const cursor = Cursor.from(data, (nextValue, prevValue, keyPath) => {
console.log('Value changed from', prevValue, 'to', nextValue, 'at', keyPath);
});
// Multiple update transactions are serialised.
cursor.set('a', 2);
// Value changed from Map { a: 1, b: 2 } to Map { a: 2, b: 2 } at [ 'a' ]
cursor.set('b', 3);
// Value changed from Map { a: 2, b: 2 } to Map { a: 2, b: 3 } at [ 'b' ]
// Whilst the cursor the itself stays immutable.
cursor.deref(); // => Map { "a": 1, "b": 2 }
This has far reaching consequences when used in component-centric view layers such as React. A typical use case
would be to make several derivations of a cursor within a React component before propagating them down the
sub-tree as props.
masternpm installdist files; this, a test run and a linting pass is done automatically every time you make a commit.FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.