
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
@astrojs/sitemap
Advanced tools
This Astro integration generates a sitemap based on your pages when you build your Astro project.
Read the @astrojs/sitemap docs
Get help in the Astro Discord. Post questions in our #support forum, or visit our dedicated #dev channel to discuss current development and more!
Check our Astro Integration Documentation for more on integrations.
Submit bug reports and feature requests as GitHub issues.
This package is maintained by Astro's Core team. You're welcome to submit an issue or PR! These links will help you get started:
MIT
Copyright (c) 2023–present Astro
The 'sitemap' package is a general-purpose sitemap generator for Node.js. It offers a wide range of customization options and can be used with various frameworks. Compared to @astrojs/sitemap, it is more versatile but requires more manual setup.
The 'next-sitemap' package is specifically designed for Next.js projects. It provides an easy way to generate sitemaps with minimal configuration. While it offers similar functionalities to @astrojs/sitemap, it is tailored for Next.js rather than Astro.
The 'gatsby-plugin-sitemap' package is a plugin for Gatsby projects that generates sitemaps automatically. It is similar to @astrojs/sitemap in terms of ease of use and integration but is specific to Gatsby.
FAQs
Generate a sitemap for your Astro site
The npm package @astrojs/sitemap receives a total of 259,441 weekly downloads. As such, @astrojs/sitemap popularity was classified as popular.
We found that @astrojs/sitemap demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.