
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
@tapjs/clock
Advanced tools
A deterministic mock clock for use in tests involving time.
A mock clock will be available at t.clock. If you call
t.clock.enter(), it will monkey-patch all the globals to be
tied to the deterministic mock clock implementation. When the
test completes, the patched globals will return to their previous
state automatically.
Add the plugin by running:
tap plugin add @tapjs/clock
Then, you can use it by accessing the t.clock object on any
test, which is an instance of the Clock
class.
For example:
t.test('some timers and such', async t => {
t.clock.enter()
let timeoutFired = false
setTimeout(() => (timeoutFired = true), 100)
t.clock.advance(50)
t.equal(timeoutFired, false)
t.clock.advance(50)
t.equal(timeoutFired, true)
})
If you aren't using the @tapjs/after plugin, then you'll have
to call t.clock.exit() at some point to restore the global
timers to their previous states if you enter it.
See clock-mock for full API details.
FAQs
a make believe clock for tests involving time
We found that @tapjs/clock demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.