
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@dp-websolutions/laravel-translator
Advanced tools
This module implements a function that can parse laravel localization strings.
This module implements a function that can parse laravel localization strings.
https://laravel.com/docs/9.x/localization
npm install @dp-websolutions/laravel-translator
This module will expose a Translator function that creates a translator instance.
You can load this module in different ways:
Load the script directly into a page
<script src="node_modules/@dp-websolutions/laravel-translator/dist/laravel-translator.umd.js"></script>In a compilation step, that will later generate a javascript bundle and loaded into a page
const {Translator} = require('@dp-websolutions/laravel-translator')Using imports
import {Translator} from '@dp-websolutions/laravel-translator'Then you can initialize the Translator:
const strings = {
welcome: "Welcome :name",
};
const translator = Translator(strings);
const text = translator.__("welcome", { name: "Carlos" });
console.log(text); // Welcome Carlos
To develop locally, clone the repository and run the following commands from within the directory
npm run installnpm run devlocalhost:8080 any changes will automatically reload the pageTo run tests and watch for file changes
npm run test:dev
For a single test run
npm run test
To check the test coverage run
npm run coverage
FAQs
This module implements a function that can parse laravel localization strings.
We found that @dp-websolutions/laravel-translator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A malicious package uses a QR code as steganography in an innovative technique.

Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.

Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.