
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@glue42/web-platform
Advanced tools
A Web Platform application (or "Main application") in the context of Glue42 Core is a web application that uses the @glue42/web-platform
package. This app is responsible for configuring the entire Glue42 environment and acts as a central hub for all Web Client apps in your Glue42 Core project. All Glue42 operations are routed through this Main application, meaning that this is the place where you can get centralized logging, information about all operations and details about the general state of your project. The configuration for all Glue42 libraries (e.g., Application Management, Layouts, Workspaces, Plugins, Notifications) is handled here.
The Main application also provides tracking and control over non-Glue42 applications opened through it. The level of control is limited, but all basic operations are available - open, close, receiving events, listing, adding and manipulating via Workspaces.
If the Main application is closed, all Web Client applications will lose their connection to Glue42 and therefore - all Glue42 capabilities. Opening the Main app again won't reestablish the connection, because this will effectively be an entirely new window with a new session and new context. However, if the Main application is refreshed, the existing Web Client apps will detect that and will reconnect as soon as the Main app is back online.
FAQs
Glue42 Core main application package
We found that @glue42/web-platform demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.