
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
CLI to check your project's ESM support status
Run the following command in your project root:
pnpx are-we-esm
[!NOTE] Only works with pnpm projects
--simple
- Simpiled the module type to CJS
and ESM
. Consider DUAL
as ESM, FAUX
as CJS (default: false)--prod
- Check only the production dependencies--dev
- Check only the development dependencies--exclude
- Exclude packages from the check, e.g. --exclude="eslint,eslint-*,@eslint/*"
--all
- Print all packages, including those that are ESM compatible (default: false)--list
- Print the flat list of packages, instead of tree (default: false)--depth
- Limit the depth search of the tree (default: 25)--prod
flag by traversing the treeThanks to the following projects and their authors for inspiration:
MIT License © 2025-PRESENT Anthony Fu
FAQs
CLI to check your project's ESM support status
We found that are-we-esm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.