
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@snowplow/browser-plugin-enhanced-ecommerce
Advanced tools
Browser Plugin to be used with @snowplow/browser-tracker
.
Adds enhanced ecommerce events to your Snowplow tracking.
Part of the Snowplow JavaScript Tracker monorepo.
Build with Node (10+) and Rush.
$ npm install -g @microsoft/rush
$ git clone https://github.com/snowplow/snowplow-javascript-tracker.git
$ rush update
With npm:
npm install @snowplow/browser-plugin-enhanced-ecommerce
Initialize your tracker with the EnhancedEcommercePlugin:
import { newTracker } from '@snowplow/browser-tracker';
import { EnhancedEcommercePlugin } from '@snowplow/browser-plugin-enhanced-ecommerce';
newTracker('sp1', '{{collector}}', { plugins: [ EnhancedEcommercePlugin() ] }); // Also stores reference at module level
Then use the available functions from this package to track to all trackers which have been initialized with this plugin:
import { addEnhancedEcommerceProductContext, addEnhancedEcommercePromoContext, trackEnhancedEcommerceAction } from '@snowplow/browser-plugin-enhanced-ecommerce';
addEnhancedEcommerceProductContext({
id: 'P12345',
name: 'Blue T-Shirt',
list: 'Search Results',
brand: 'The T-Shirt Company',
category: 'Apparel/T-Shirts',
variant: 'Black',
quantity: 1,
});
addEnhancedEcommercePromoContext({
id: 'PROMO_1234',
name: 'Summer Sale',
creative: 'summer_banner2',
position: 'banner_slot1',
});
trackEnhancedEcommerceAction({ action: 'purchase' });
Licensed and distributed under the BSD 3-Clause License (An OSI Approved License).
Copyright (c) 2021 Snowplow Analytics Ltd, 2010 Anthon Pang.
All rights reserved.
FAQs
Enhanced Ecommerce tracking for Snowplow
The npm package @snowplow/browser-plugin-enhanced-ecommerce receives a total of 3,001 weekly downloads. As such, @snowplow/browser-plugin-enhanced-ecommerce popularity was classified as popular.
We found that @snowplow/browser-plugin-enhanced-ecommerce demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.