
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@huangang/cordova-plugin-webview-x5
Advanced tools
把Cordova
的WebView
替换为腾讯的X5。使用腾讯浏览服务TBS完整版SDK。
cordova plugin add @huangang/cordova-plugin-webview-x5
com.tencent.tbs:tbssdk:44226
此项目继承自项目:https://github.com/runner525/x5webview-cordova-plugin.git
此项目参照的互联网上若干项目
与本项目有关的问题,如加载后无法正常启动,在本项目Issue区内提交新Issue即可。
X5相关问题,请参阅:X5技术指南
请使用官方TBS Studio测试,如其安装的TBS Demo左上角仍显示Sys core
,证明X5内核可能无法被第三方App调用。请参阅X5技术指南或反馈到X5官方。
当手机上有宿主(QQ、微信或QQ空间)时,其他AP只要接入了x5的SDK就会去共享宿主的内核,当没有宿主或是宿主都没有可用的内核时会自己去下载内核
官网(https://x5.tencent.com/tbs/)
FAQs
Changes the default WebView to x5
The npm package @huangang/cordova-plugin-webview-x5 receives a total of 9 weekly downloads. As such, @huangang/cordova-plugin-webview-x5 popularity was classified as not popular.
We found that @huangang/cordova-plugin-webview-x5 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.