
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@appsignal/nodejs
Advanced tools
- [AppSignal.com website][appsignal] - [Documentation][docs] - [Support][contact]
The core AppSignal for Node.js library.
Please follow our installation guide in our documentation.
First, sign up for an AppSignal account and run our automated install tool, which will install @appsignal/nodejs
and any relevant integrations to your project:
npx @appsignal/cli install
You can also skip the automated tool and add @appsignal/nodejs
to your package.json
on the command line with npm
/yarn
:
yarn add @appsignal/nodejs
npm install --save @appsignal/nodejs
Alternatively, you can manually add the @appsignal/nodejs
package to your package.json
. Then, run yarn install
/npm install
.
Installing the AppSignal for Node.js integration builds a native extension. In order to compile it, macOS users will need to install the Xcode Developer Tools. Linux users will need the dependencies outlined here. Windows is not supported.
You can then import and use the package in your bundle:
const { Appsignal } = require("@appsignal/nodejs");
const appsignal = new Appsignal({
active: true,
name: "<YOUR APPLICATION NAME>",
pushApiKey: "<YOUR API KEY>"
});
// ...all the rest of your code goes here!
In order to auto-instrument modules, the Appsignal module must be both required and initialized before any other package.
This package also contains the C++ extension, and the install script for the agent. The native extension is a bridge between the Node.js runtime and our agent.
This repository is a mono-managed repository. First install mono on your local machine by following the mono installation steps.
Then install the dependencies and prepare the project for development use using mono:
mono bootstrap
You can then run the following to start the compiler in watch mode.
npm run build:watch --parallel
You can also build the library without watching the directory:
mono build
Version management configuration is provided for asdf
.
The tests for this library use Jest as the test runner. Once you've installed the dependencies, you can run the following command in the root of this repository to run the tests for all packages, or in the directory of a package to run only the tests pertaining to that package:
mono test
Thinking of contributing to this repo? Awesome! 🚀
Please follow our Contributing guide in our documentation and follow our Code of Conduct.
Also, we would be very happy to send you Stroopwafels. Have look at everyone we send a package to so far on our Stroopwafels page.
Contact us and speak directly with the engineers working on AppSignal. They will help you get set up, tweak your code and make sure you get the most out of using AppSignal.
FAQs
The AppSignal for Node.js library.
The npm package @appsignal/nodejs receives a total of 11,928 weekly downloads. As such, @appsignal/nodejs popularity was classified as popular.
We found that @appsignal/nodejs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.