
Research
/Security News
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
android dev the simple way. take a set of html files, and turn them into an apk with one command. Proof of Concept.
dabbling occasionally in android dev... is a massive pain in the butt! why can't it just be easy? why do I have to install massive SDKs and all that crap? Since I only want to build my app with web tech, why isn't it as easy as creating a web site?
write some HTML and javascript, then hit deploy?
Then I had an idea: instead of recompiling the stupid java app from scratch every time (and requiring the enormous android sdk) just use a prebuilt apk, replace the text files, repack and resign.
Turns out, this was surprisingly easy.
npm install androidify -g
Almost, you'll also need to have java, to get the jarsigner
command, and adb
command to deploy your app.
sudo apt-get install default-jre android-tools-adb
sudo pacman -S jre8-openjdk-headless android-tools
brew cask install java android-platform-tools
and put your phone into developer mode (depends on your phone)
mkdir hello
echo '<h1> HELLO </h1>' > index.html
androidify #will output app.apk
adb install app.apk # will send it to your device.
A new app called "Hello World" will appear.
I havn't figured out how to change the name yet. So, it's called "Hello World" no matter what.
The apps are selfsigned, which is basically meaningless, so I just checked the key it in. My phone doesn't complain about this, maybe because it's in developer mode?
This is made an old hello world.apk
i found at
simplificator/phonegap-helloworld
MIT
FAQs
convert html/javascript files into an android app
The npm package androidify receives a total of 0 weekly downloads. As such, androidify popularity was classified as not popular.
We found that androidify demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
Security News
Meet Socket at Black Hat & DEF CON 2025 for 1:1s, insider security talks at Allegiant Stadium, and a private dinner with top minds in software supply chain security.
Security News
CAI is a new open source AI framework that automates penetration testing tasks like scanning and exploitation up to 3,600× faster than humans.