
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
active-win
Advanced tools
Get metadata about the active window and open windows (title, id, bounds, owner, URL, etc)
Get metadata about the active window and open windows (title, id, bounds, owner, URL, etc)
Works on macOS 10.14+, Linux (note), and Windows 7+.
npm install active-win
This is an ESM package which requires you to use ESM
import {activeWindow} from 'active-win';
console.log(await activeWindow(options));
/*
{
title: 'Unicorns - Google Search',
id: 5762,
bounds: {
x: 0,
y: 0,
height: 900,
width: 1440
},
owner: {
name: 'Google Chrome',
processId: 310,
bundleId: 'com.google.Chrome',
path: '/Applications/Google Chrome.app'
},
url: 'https://sindresorhus.com/unicorn',
memoryUsage: 11015432
}
*/
Get metadata about the active window.
Type: object
Type: boolean
Default: true
Enable the accessibility permission check. Setting this to false
will prevent the accessibility permission prompt on macOS versions 10.15 and newer. The url
property won't be retrieved.
Type: boolean
Default: true
Enable the screen recording permission check. Setting this to false
will prevent the screen recording permission prompt on macOS versions 10.15 and newer. The title
property in the result will always be set to an empty string.
Get metadata about the active window synchronously.
Returns a Promise<object>
with the result, or Promise<undefined>
if there is no active window or if the information is not available.
platform
(string) - 'macos'
| 'linux'
| 'windows'
title
(string) - Window titleid
(number) - Window identifierbounds
(Object) - Window position and size
x
(number)y
(number)width
(number)height
(number)owner
(Object) - App that owns the window
name
(string) - Name of the appprocessId
(number) - Process identifierbundleId
(string) - Bundle identifier (macOS only)path
(string) - Path to the appurl
(string?) - URL of the active browser tab if the active window (macOS only)
memoryUsage
(number) - Memory usage by the window owner processGet metadata about all open windows.
Windows are returned in order from front to back.
Returns Promise<Result[]>
.
Get metadata about all open windows synchronously.
Windows are returned in order from front to back.
Returns Result[]
.
It works on macOS 10.14+, Linux, and Windows 7+.
Note: On Windows, there isn't a clear notion of a "Window ID". Instead it returns the memory address of the window "handle" in the id
property. That "handle" is unique per window, so it can be used to identify them. Read more…
Wayland is not supported. For security reasons, Wayland does not provide a way to identify the active window. Read more…
If you use this package in an Electron app that is sandboxed and you want to get the .url
property, you need to add the proper entitlements and usage description.
To bypass the gyp
build:
npm install --ignore-scripts
FAQs
Get metadata about the active window and open windows (title, id, bounds, owner, URL, etc)
The npm package active-win receives a total of 681 weekly downloads. As such, active-win popularity was classified as not popular.
We found that active-win demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.