
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@mxenabled/widget-post-message-definitions
Advanced tools
Widget Post Message Definitions for use in SDKs
This project defines and implements all Post Message parsing and dispatching in TypeScript. This is for use in Widget SDKs. The majority of this package was auto generated by the Widget Post Message Definitions project, and any modifications to a Post Message definition or handling should be done there.
You can install this package via npm:
npm install --save @mxenabled/widget-post-message-definitions
import { dispatchConnectLocationChangeEvent } from "@mxenabled/widget-post-message-definitions"
dispatchConnectLocationChangeEvent("mx://connect/memberDeleted?metadata=...", {
onMemberDeleted: (payload) => {
console.log(`${payload.member_guid} has been deleted`)
}
})
This package does not have any dependencies with the exception of the url
package, which you may need if you're parsing post message events from URL
change events.
The React Native SDK needs this package and has it as a dependency, but the Web SDK won't and we shouldn't install or import it. This allows us to keep both SDKs happy.
To install url
in your project so you can parse post messages in location
change events:
npm install --save url
FAQs
Widget Post Message Definitions for use in SDKs
We found that @mxenabled/widget-post-message-definitions demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 23 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.