
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@trimble-oss/modus-bootstrap
Advanced tools
Several quick start options are available:
git clone https://github.com/trimble-oss/modus-bootstrap.gitnpm install @trimble-oss/modus-bootstrapyarn add @trimble-oss/modus-bootstrapFor transparency into our release cycle and in striving to maintain backward compatibility, Modus Bootstrap is maintained under the Semantic Versioning guidelines.
See the Releases section of our GitHub project for changelogs for each release version.
Our default branch (main) is for development of our Modus Bootstrap v2 release.
Code and documentation copyright 2011-2025 the Bootstrap Authors. Code released under the MIT License. Docs released under Creative Commons.
Modus Bootstrap code and documentation copyright 2025 Trimble Inc. Code released under the MIT License. Docs released under Creative Commons.
FAQs
Modus Bootstrap 2 based on Bootstrap v5.x
We found that @trimble-oss/modus-bootstrap demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.