
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
@sailshq/eslint
Advanced tools
A fork of eslint v4.19.1 with ongoing maintenance from the Sails core team.
This repo will only be updated when there are immediate, material issues affecting expected usage, or annoying NPM deprecation warnings, like this one. Our goal is to diverge as little as possible.
In other words, there will never be any new methods or options added to eslint on this fork, and consequently there will be no minor version or major version bumps from this fork-- only patches.
To report a bug, click here.
Please observe the guidelines and conventions laid out in the Sails project contribution guide when opening issues or submitting pull requests.
eslint is free and open source under the MIT License.
All ad hoc additions in this repo are also MIT-licensed, copyright © 2018 The Sails Company.
The Sails framework is free and open-source under the MIT License.
FAQs
An AST-based pattern checker for JavaScript.
We found that @sailshq/eslint demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.