Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
@reown/appkit-cli
Advanced tools
AppKit CLI is a command-line tool to fast download a funcionaly boilerplate example for Reown Web AppKit SDK.
To install this CLI tool globally for development, you can link it locally using the following commands.
First, clone this repository to your local machine:
git clone https://github.com/reown-com/appkit-cli
cd appkit-cli
To test the CLI locally, use npm link
. This allows you to run the CLI from any location on your machine.
npm install
sudo npm link
Once linked, you can use the CLI globally by running:
appkit-cli
Also you can run it directly:
npx appkit-cli
Provide examples of some paramaeters:
appkit-app [project-name]
For example:
appkit-app my-app
appkit-app
If you want to work on the CLI and test it locally without publishing, use npm link
:
Navigate to the Project Directory:
cd path/to/appkit-cli
Run npm link:
sudo npm link
To remove the symlink and unlink the CLI, use:
sudo npm unlink -g
This will unregister the global command appkit-cli
, but it won’t delete any files in your project directory.
https://github.com/user-attachments/assets/6c4fbdc3-c0ca-4edd-a730-20cfee878c86
FAQs
Reown AppKit CLI
The npm package @reown/appkit-cli receives a total of 297 weekly downloads. As such, @reown/appkit-cli popularity was classified as not popular.
We found that @reown/appkit-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.