
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@zappar/cra-template-r3f-image-tracking-typescript
Advanced tools
Template for Zappar for React Three
In this project you'll find an Node.js project that gets you up and running with Zappar for React-Three-Fiber.
Head to the NPM package page for more information on how to build best-in-class AR experiences: Zappar for React-Three-Fiber (@zappar/zappar-react-three-fiber)
Scan the QR code below using your native camera app or QR code reader to view the example:
![]()
The project has been set up to use webpack for bundling assets and code. To get started, install the project's dependencies by running the following command:
npm install
During development, you can use the following command to run a webpack server for testing on your computer or a device on your local network:
npm run start
And when you're ready to publish your site, run the following command. The resulting dist folder can be uploaded to ZapWorks for publishing. If you'd like to self-host your site, be sure to check out the documentation on the Zappar for React Three Fiber page.
npm run build
![]()
FAQs
Template for Zappar for React Three
The npm package @zappar/cra-template-r3f-image-tracking-typescript receives a total of 2 weekly downloads. As such, @zappar/cra-template-r3f-image-tracking-typescript popularity was classified as not popular.
We found that @zappar/cra-template-r3f-image-tracking-typescript demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 10 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.