
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@fizker/serve
Advanced tools
A static file HTTP server, designed to be running in Docker.
It has no dependencies and does as little work as possible in order to serve files. This is achieved by running a tool like @fizker/serve-prepare first to prepare the files.
See @fizker/serve-prepare for how to prepare the Docker container. Once the container is built, execute the following command: docker run -p <desired HTTP port>:8080 -p <desired HTTPS port>:8081 -d <your docker user>/<your project name>
Internally, the server is configured to run on port 8080 per default, which is why the -p <desired HTTP port>:8080
ends with 8080
. If desired, the port can be changed by either altering the Dockerfile or by adding -e PORT=8080
to the run command. Services such as Heroku will also change the port as they require.
The 8081
port is used for HTTPS connections. It can be configured in a manner similar to the HTTP port. If HTTPS support is not wanted, or you have not set up the certificates yet, that portion can be omitted to avoid exposing an unused port to the Docker container.
FAQs
A static file HTTP server
We found that @fizker/serve demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.