Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
ac-koa-hipchat
Advanced tools
A Node.js and Koa.js-based library for building HipChat Connect add-ons.
While this is still a pre-1.0 release, the API has mostly stabilized. Future versions may still include backward-incompatible changes, but the risk of that now is relatively low.
To create and install a simple HipChat add-on, please see our Getting Started guide.
The example illustrated in the Getting Started guide comes from the following example project:
See these additional add-ons for more complete examples:
This library provides help with many aspects of add-on development, such as:
In these documentation pages, we use the terms ctx
and 'Koa context' interchangeably to refer to the context object that contains both standard Koa request/response data and objects and this library's request objects and services.
Frequently asked questions, helpers and tips: FAQ
FAQs
A Koa.js library for building Atlassian Connect HipChat add-ons
The npm package ac-koa-hipchat receives a total of 3 weekly downloads. As such, ac-koa-hipchat popularity was classified as not popular.
We found that ac-koa-hipchat demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.