Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@wiris/mathtype-html-integration-devkit
Advanced tools
Allows to integrate MathType Web into any JavaScript HTML WYSIWYG rich text editor.
Install dependencies:
$ yarn install
Compile using npm packages:
$ yarn run build
Compile using local packages:
$ yarn run build-dev
Lint:
$ yarn run lint
Test:
$ yarn run test
The following packages are dependencies of the project:
In order to conform to RFC specifications when generating UUIDs, we leverage this package instead of maintaining all the logic that is unrelated to MathType.
Used to sanitize HTML and prevents XSS attacks. When HTML code is sent by the user, DOMPurify receive the input and delete the malicious code.
This project uses jsdoc
to build an HTML documentation site of this package and its API.
The jsdoc
theme for this site is mathtype-integration-jsdoc-theme.
How to generate the documentation site
Run these commands:
$ yarn install
$ yarn run build-jsdoc
The source code of the documentation site is generated on the /out
folder.
The MathType Privacy Policy covers the data processing operations for the MathType users. It is an addendum of the company's general Privacy Policy and the general Privacy Policy still applies to MathType users.
FAQs
Allows to integrate MathType Web into any JavaScript HTML WYSIWYG rich text editor.
The npm package @wiris/mathtype-html-integration-devkit receives a total of 8,399 weekly downloads. As such, @wiris/mathtype-html-integration-devkit popularity was classified as popular.
We found that @wiris/mathtype-html-integration-devkit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.