
Research
/Security News
npm Package Uses Prompt Injection and Token Flooding to Disrupt AI Malware Scanners
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.
github.com/xiaomingxd/sakurafrp
Advanced tools
此项目为 fatedier/frp 衍生项目,如需了解原版 Frp,请前往官方仓库。
Sakura Frp 是一个基于 frp 的二次开发项目,在原版的基础上增加了限速、流控以及对接网站的功能,可实现商业化运营。
安装可选两种方式,下载 Release 页面上已经编译好的版本或者自行编译。
编译方法(编译过程需要科学上网):
git clone https://github.com/ZeroDream-CN/frp
cd frp/
make
默认配置文件请访问 Wiki 页面的 Configuration 子页面。
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.

Product
Socket now detects supply chain risks in project manifests, starting with missing lockfiles that can make dependency installs non-reproducible.

Research
/Security News
The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.