
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
@storybook/vue3
Advanced tools
Storybook Vue 3 renderer: Develop, document, and test UI components in isolation
Develop, document, and test UI components in isolation.
Learn more about Storybook at storybook.js.org.
Vue Styleguidist is a component development environment with a focus on documentation. It allows developers to create and maintain a living style guide for Vue components. Compared to @storybook/vue3, Vue Styleguidist is more focused on documentation and less on interactive component development.
Docz is a documentation tool that supports multiple frameworks, including Vue. It allows developers to create interactive documentation for their components. While it provides similar documentation capabilities as @storybook/vue3, it is more general-purpose and not specifically tailored for Vue 3.
Vue Play is a minimalistic library for developing and testing Vue components in isolation. It offers a simpler and more lightweight alternative to @storybook/vue3, but lacks some of the advanced features and add-ons that Storybook provides.
FAQs
Storybook Vue 3 renderer: Develop, document, and test UI components in isolation
We found that @storybook/vue3 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 12 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.