Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
org.webjars.npm:rmwc__avatar
Advanced tools
⚡️ Attention: This project is currently being brought back to life. If you're interested in helping with maintenance and becoming a contributor or maintainer, please message on Discord.
RMWC is a React UI Kit built on Google's official Material Components Web library v8.x.x https://rmwc.io/
Features:
- Javascript Sandbox https://codesandbox.io/s/rmwc-sandbox-o0s0d
- Typescript Sandbox https://codesandbox.io/s/rmwc-typescript-sandbox-y7516
v8.0.1 is here! This release includes bug fixes of v8.0.0.
npm i rmwc@latest
or npm i @rmwc/button@latest
.View all release notes 👉 https://opencollective.com/rmwc/updates
View the changelog for detailed updates: https://github.com/jamesmfriedman/rmwc/blob/master/CHANGELOG.md
npm i rmwc --save
or yarn add rmwc
Additional information is available in the Installation Guide
Read the docs on how to Usage
Read the docs on Methodology
RMWC avoids them at all costs! Read the docs on Methodology
brew install watchman
npm test
git clone https://github.com/jamesmfriedman/rmwc.git
cd rmwc
npm install
npm start
This project exists thanks to all the people who contribute. [Contribute].
Thank you to all our backers! 🙏 We are no longer accepting financial contributions, and the remaining balance in our Open Collective will go to help efforts in the Ukraine. Thank you to all of our previous backers!
Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]
FAQs
WebJar for @rmwc/avatar
We found that org.webjars.npm:rmwc__avatar demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.