
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
github.com/vace/css3-animation-generator
快速给页面加上炫酷css3动画的chrome插件。
如果无法访问到chrome的应用商城,可以选择下载app.crx
文件,在chrome中打开chrome://extensions/
页面,将app.crx
插件拖动到扩展程序面板即可完成安装。
下载地址
npm install -g vue-cli
git clone https://github.com/vace/css3-animation-generator
cd css3-animation-generator && npm install
npm run app
c3
前缀的class,如 <span class="c3-test">animate it</span>
<span class="fl animate">animate it</span>
<span id="anim1">animate it</span>
部分脚本中使用了 javascript 的Set
,请尽量升级 chrome 到比较新的版本。测试使用的chrome48+都可以正常使用!导出的动画可能需要加前缀才可以兼容所有浏览器,推荐使用autoprefix,后期考虑加入这个功能。
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.