
Research
/Security News
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
@types/webxr
Advanced tools
TypeScript definitions for webxr
npm install --save @types/webxr
This package contains type definitions for webxr (https://www.w3.org/TR/webxr/).
Files were exported from https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/webxr.
These definitions were written by Rob Rohan, Raanan Weber, Sean T. McBeth, and Timmy Kokke.
Three.js is a popular JavaScript library for creating 3D graphics on the web. It provides higher-level abstractions for 3D rendering and includes support for WebXR, making it easier to create VR and AR experiences. Compared to @types/webxr, Three.js offers more comprehensive tools for 3D graphics but is less focused on type definitions.
A-Frame is a web framework for building virtual reality experiences. It is built on top of Three.js and provides an easy-to-use, declarative syntax for creating VR scenes. A-Frame abstracts away much of the complexity of WebXR, making it more accessible for beginners. Unlike @types/webxr, A-Frame is more about simplifying VR development rather than providing type definitions.
Babylon.js is a powerful, open-source 3D engine that supports WebXR. It provides a comprehensive set of tools for creating 3D applications, including VR and AR experiences. Babylon.js offers more features for 3D graphics and game development compared to @types/webxr, which focuses on type definitions for the WebXR API.
FAQs
TypeScript definitions for webxr
The npm package @types/webxr receives a total of 3,397,840 weekly downloads. As such, @types/webxr popularity was classified as popular.
We found that @types/webxr demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.

Research
/Security News
Docker and Socket have uncovered malicious Checkmarx KICS images and suspicious code extension releases in a broader supply chain compromise.

Product
Stay on top of alert changes with filtered subscriptions, batched summaries, and notification routing built for triage.