
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@fw-components/trackers
Advanced tools
A utility that traverses the DOM and registers listeners to elements (even those present within shadowDOMs) from a provided list of events that are to be tracked.
The consumer can either provide a store configuration and the events will be fetched and parsed from the store or an array of events to be tracked.
Schema of an event-config:
{
"jsPath": "document.querySelector...",
"location": "/dashboard", // glob pattern of the url where the target-element is to be tracked
"title": "Clicked at dashboard edit-button",
"event": "click" // type of event | All js events are supported
}
const tracker = new Trackers({
store: {
type: "notion",
context: {
url: "URL_TO_RETRIEVE_NOTION_DB",
pageId: "<<PAGE_ID>>",
},
},
track: yourTrackingMethod,
debug: true,
});
tracker.initialize();
tracking multiple targets is also supported. Use :nth-child(+)
identifier to highlight elements whose multiple instances are to be tracked
Supported selector
document.querySelector("div > div.main-content > div.page > route-page > request-grid:nth-child(+)")
FAQs
Usage trackers for web components
The npm package @fw-components/trackers receives a total of 54 weekly downloads. As such, @fw-components/trackers popularity was classified as not popular.
We found that @fw-components/trackers demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.