
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@rrweb/types
Advanced tools
This package contains the shared types used across rrweb packages. See the [guide](../../guide.md) for more info on rrweb.
This package contains the shared types used across rrweb packages. See the guide for more info on rrweb.
Become a sponsor and get your logo on our README on Github with a link to your site.
|
Yuyz0112 |
Yun Feng |
eoghanmurray |
Juice10 open for rrweb consulting |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
TypeScript is a superset of JavaScript that adds static types. While it doesn't provide specific types for rrweb, it allows you to define your own types and interfaces, offering flexibility and type safety in your projects.
io-ts is a runtime type system for IO decoding/encoding in TypeScript. It allows you to define types and validate data at runtime, which can be useful for ensuring the correctness of data structures similar to those used in rrweb.
Zod is a TypeScript-first schema declaration and validation library. It provides a way to define and validate data structures, similar to the type definitions provided by @rrweb/types, but with additional runtime validation capabilities.
FAQs
This package contains the shared types used across rrweb packages. See the [guide](../../guide.md) for more info on rrweb.
The npm package @rrweb/types receives a total of 1,429,516 weekly downloads. As such, @rrweb/types popularity was classified as popular.
We found that @rrweb/types demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.