
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
@skroutz/susuro
Advanced tools
This service provides server-side rendering (SSR) for React components using Node.js worker threads. Each worker runs in its own OS thread, enabling efficient CPU-bound rendering across multiple cores. Communication between the main process and workers is handled via message passing.
Set the following environment variables to configure the service:
SSR_BUNDLE (required): Path to the SSR bundle with your React components.SSR_PORT or PORT (optional): Port for the HTTP server (default: 3030).SSR_POOL_SIZE (optional): Number of worker threads to spawn (default: 1).NODE_ENV (optional): Set to development to enable bundle watching.Start the service:
SSR_BUNDLE={rel_path_to_bundle_file} ./bin/ssr-service.mjs
Run tests:
yarn test
Lint and auto-fix code:
yarn lint:fix
FAQs
Server-side rendering service for Skroutz
The npm package @skroutz/susuro receives a total of 339 weekly downloads. As such, @skroutz/susuro popularity was classified as not popular.
We found that @skroutz/susuro demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.