Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@chrisguest75/npx_palette
Advanced tools
Demonstrates creating a basic npx cmdline tool.
TODO:
Simple steps to recreate and push to github and npm
git init
npm init --scope=@chrisguest75
# without parameters
npm run start
# with parameters
npm run start -- --info
After writing some code you can publish it.
# make sure you update the package version in package.json before updating
npm publish --access public
Run the published package
npx @chrisguest75/npx_palette
# run from a gist
npx https://gist.github.com/zkat/4bc19503fe9e9309e2bfaa2c58074d32
# run from a gist
npx https://gist.github.com/Tynael/0861d31ea17796c9a5b4a0162eb3c1e8
FAQs
Copy the code to a gist.
We found that @chrisguest75/npx_palette demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.