
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
@appium/execute-driver-plugin
Advanced tools
Plugin for batching and executing Appium driver commands
Appium plugin for running a driver script in a child process
This plugin adds a new driver command that allows executing scripts in a child process. Currently,
the only supported driver type is webdriverio, therefore the script must also be written in JS.
Running a driver script in a child process adds a degree of parallelisation, which may result in faster test execution.
[!WARNING] This plugin enables execution of arbitrary JavaScript code. We recommend only using this plugin in a controlled environment. Scripts run in a Node.js
vmcontext with a hardened view of the WebdriverIO driver (host-realm prototype metadata is not exposed), butvmis still not a full security boundary for untrusted code; treat--allow-insecure=…:execute_driver_scriptas highly privileged.
appium plugin install execute-driver
The plugin must be explicitly activated when launching the Appium server. Since the input script can be arbitrary JavaScript, this is an insecure feature, and must also be explicitly enabled:
appium --use-plugins=execute-driver --allow-insecure=<driver>:execute_driver_script
<driver> is the name of the driver whose sessions will have access to the plugin.
const script = `return await driver.getTimeouts();`;
const {result, logs} = await driver.executeDriverScript(script);
// 'result' contains the data returned by the script (in this case, the response to 'getTimeouts')
// 'logs' contains everything logged to console during script execution
Refer to your Appium client documentation for the exact syntax of the script execution command.
Since plugin version 6.0.0, scripts can also use the setTimeout/clearTimeout methods,
enabling the use of unconditional delays:
// this will take around one second to execute
const script = `return await new Promise((resolve) => setTimeout(resolve, 1000));`;
Apache-2.0
FAQs
Plugin for batching and executing Appium driver commands
The npm package @appium/execute-driver-plugin receives a total of 32,687 weekly downloads. As such, @appium/execute-driver-plugin popularity was classified as popular.
We found that @appium/execute-driver-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.