
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
@barebones/a11y-skipper
Advanced tools
A skip menu generation plugin inspired by the robust LinkedIn skip menu
If any ID passed into the Skipper.init() object are not present on the current page they will not show up in the menu.
NPM installation is not currently optimal, but you can manually install it for now by copying the files into your workflow.
import Skipper from '@barebones/a11y-skipper';
Skipper.init( {
targetElement: '#a11y-catcher',
primary: ['Skip to content', '#main'],
secondary: ['Skip to search', '#search'],
menu: [
{ label: 'Navigation', id: '#nav' },
{ label: 'Sidebar', id: '#sidebar' },
{ label: 'Footer', id: '#footer' } // this is not in the HTML, so it won't show up
],
open: false // show/hide the menu by default
} );
@import '@barebones/a11y-skipper'; /* when NPM install is fixed */
/* Update the color variables if you want */
:root {
--c-branding: black;
--c-branding-inverse: white;
}
/* Add more CSS here if you need to override anything */
<!--Matches the ID passed into Skipper.init()-->
<div id="a11y-catcher">
<!--A no-JS fallback skip link-->
<a href="#main">skip to content</a>
</div>
<!--Matches the secondary string ID passed into Skipper.init()-->
<div id="search">Your search stuff here.</div>
<!--Matches the primary string ID passed into Skipper.init()-->
<div id="main">Your main content here.</div>
FAQs
A skip menu generation plugin inspired by the robust LinkedIn skip menu
We found that @barebones/a11y-skipper demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.