
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Plugin with basic operations for pf, the fast and extensible command-line data (e.g. JSON) processor and transformer
@pfx/base
is a plugin with basic operations for pf
, the fast and extensible command-line data (e.g. JSON) processor and transformer.
See the pf
github repository for more details!
:ok_hand:
@pfx/base
comes preinstalled inpf
. No installation necessary. If you still want to install it, proceed as described below.
@pfx/base
is installed in ~/.pfrc/
as follows:
npm install @pfx/base
The plugin is included in ~/.pfrc/index.js
as follows:
const base = require('@pfx/base')
module.exports = {
plugins: [base],
context: {},
defaults: {}
}
For a much more detailed description, see the .pfrc
module documentation.
This plugin comes with the following pf
extensions:
Description | |
---|---|
line lexer | Divides data on line breaks. A lot of data formats like CSV, TSV, and JSON line build on this separation. |
map applicator | Applies pf 's functions to each individual line. Always returns a single result, unless an error is thrown during function application. |
flatMap applicator | Applies pf 's functions to each individual line. May return any number of results, including none, thus being able to change the length of a file. |
filter applicator | Treats pf 's functions as a conjunction of predicates and applies it to each individual line. If any predicate is false, the line is dropped, if all predicates return true, the line is kept. |
string marshaller | Serializes each transformed JSON into a string separated by newlines. |
Please report issues in the tracker!
@pfx/base
is MIT licensed.
FAQs
Plugin with basic operations for pf, the fast and extensible command-line data (e.g. JSON) processor and transformer
We found that @pfx/base demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.