
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@userfrosting/sprinkle-core
Advanced tools
Copyright (c) 2013-2024, free to use in personal and commercial software as per the license.
UserFrosting is a secure, modern user management system written in PHP and built on top of the Slim Microframework, Twig templating engine, and Eloquent ORM.
This Core Sprinkle provides most of the "heavy lifting" PHP code. It provides all the necessary services for database, templating, error handling, mail support, request throttling, and more.
To use this sprinkle in your UserFrosting project, follow theses instructions (N.B.: This sprinkle is enabled by default when using the base app template).
Require in your UserFrosting project :
composer require userfrosting/sprinkle-core
Add the Sprinkle to your Sprinkle Recipe :
public function getSprinkles(): array
{
return [
\UserFrosting\Sprinkle\Core\Core::class,
];
}
Bake
php bakery bake
You can also install this sprinkle locally. This can be useful to debug or contribute to this sprinkle.
git clone https://github.com/userfrosting/sprinkle-core.git
cd sprinkle-core
composer install
php bakery bake
From this point, you can use the same command as with any other sprinkle.
Tests can be run using the bundled PHPUnit :
vendor/bin/phpunit
Same for PHPStan, for code quality :
vendor/bin/phpstan analyse app/src/
See main UserFrosting Documentation for more information.
This project exists thanks to all the people who contribute. If you're interested in contributing to the UserFrosting codebase, please see our contributing guidelines as well as our style guidelines.
FAQs
Core Sprinkle for UserFrosting
The npm package @userfrosting/sprinkle-core receives a total of 1 weekly downloads. As such, @userfrosting/sprinkle-core popularity was classified as not popular.
We found that @userfrosting/sprinkle-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.