
Research
NPM targeted by malware campaign mimicking familiar library names
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
@profabric/angular-components
Advanced tools
This component kit, offered by Profabric Tech, serves to establish a uniform and polished UI/UX for web users.
The web implementation of our component kit harnesses the power of native web components, guaranteeing seamless compatibility with a variety of web frameworks such as Vue, React, or Angular. Our primary goal is to showcase a meticulously crafted UI library, with the aim of delivering an exceptional user experience for applications that integrate Profabric Components. This UI kit stands as a flagship product within the comprehensive lineup provided by Profabric Tech.
The recommended method for utilizing Profabric Components is through the CDN. Simply import the library's JS file into your main document as illustrated below:
<script src="https://cdn.jsdelivr.net/npm/@profabric/web-components@0.2.3/dist/index.min.js"></script>
In this manner, the library will be hosted on an exceptionally high-performance CDN, ensuring that all Profabric web components are readily available for integration into your web projects.
<pf-button>Hello World!</pf-button>
FAQs
Unknown package
We found that @profabric/angular-components demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
Research
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
Research
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.