Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
@arc-fusion/content-integrations
Advanced tools
In pb-admin root folder run npm install --legacy-peer-deps
Option 1:
build within the integrations folder: In packages/content-integrations/
folder run npm run build
Option 2:
Build within the pb-admin root: In pb-admin/
run npm run build:integrations
In packages/content-integrations
run npm run build:watch
These live in the packages/content-integrations/shared/
and consist of the following types of items:
components
- React components such as checkboxes, selects, etc.icons
- JSX written SVG iconsmodules
- Generic JS functions that can be used across integrationsservices
- API callspackages/content-integrations/src/
folderIn a separate terminal go to the folder: packages/content-integrations
and run npm run build:watch
. This will build the content-integrations package when a change is made in it's structure.
Note: If something doesn't update correctly, delete the folder: packages/content-integrations/dist
. Rerun the static build step from above to re-create the dist folder. Alternatively you could also run npm run clean
within the packages/content-integrations
folder. You may need to restart your pb-admin front end to have it re-detect file changes since the dist folder is what it was aware of.
Once you've finished work on your integration and the branch is ready for merging, you will need to update the packages/content-integrations/package.json
version number and run an npm publish
in that folder to deploy the updated package.
Note: If you have issues publishing, please reach out to the team and someone can help get you set up for this action.
Next, bump the version listed in the pb-admin root package.json to match your newly deployed version and run npm install --legacy-peer-deps
to pull it in.
FAQs
Unknown package
The npm package @arc-fusion/content-integrations receives a total of 5 weekly downloads. As such, @arc-fusion/content-integrations popularity was classified as not popular.
We found that @arc-fusion/content-integrations demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 12 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.