
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Access meta data about an application.
A common feature that I include in my client side apps is meta information about the application itself. Three common values are:
This library provides a simple method to store and access those bits of data that you can use across all of your apps.
Set up your server to send over the meta data as data
attributes on the html
element. This might look like:
<html
lang='en'
data-version='<%= version %>'
data-sha='<%= sha %>',
data-env='<%= env %>'
>
Then, require in this library.
import meta from 'path/to/app-meta';
console.log(
'Got some data:',
meta.VERSION,
meta.SHA,
meta.ENV
);
Should work in IE6+
It exports UMD, so it's compatible with AMD, CJS, and as a browser global (window.meta
).
FAQs
Access meta data about an application.
The npm package app-meta receives a total of 0 weekly downloads. As such, app-meta popularity was classified as not popular.
We found that app-meta demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.