
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@bigcommerce/create-catalyst
Advanced tools
Create a new Catalyst project, and optionally connect the project to a BigCommerce store. Add `--help` to the end of any command to learn about available subcommands and options.
Create a new Catalyst project, and optionally connect the project to a BigCommerce store. Add --help
to the end of any command to learn about available subcommands and options.
[!WARNING] With yarn berry, you might run into a dependency issue with
stripAnsi
. You can circumvent this issue by setting the nodeLinker to eitherpnpm
ornode-modules
while the dependency issue is resolved.
npm create @bigcommerce/catalyst@latest
pnpm create @bigcommerce/catalyst@latest
yarn create @bigcommerce/catalyst@latest
npm create @bigcommerce/catalyst@latest init
pnpm create @bigcommerce/catalyst@latest init
yarn create @bigcommerce/catalyst@latest init
FAQs
Create a new Catalyst project, and optionally connect the project to a BigCommerce store. Add `--help` to the end of any command to learn about available subcommands and options.
We found that @bigcommerce/create-catalyst demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 11 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.