
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
Convert a series of 8-bit signed integers to 32-bit floats.
Install globally to use from the command line:
npm install b2f --global
Install as dependency to use programmatically:
npm install b2f --save
cat input.bin | b2f > output.bin
var b2f = require('b2f')
var input = new Buffer('01020304', 'hex')
var output = b2f(input)
console.log(output.toString('hex')) // 0000003c0000803c0000c03c0000003d
var output = b2f(input)Returns a Buffer object four times the size of input with each byte
converted the a 32-bit float (little endian).
It's expected that each byte in input is of type 8-bit signed integer.
MIT
FAQs
Convert a series of 8-bit signed integers to 32-bit floats
The npm package b2f receives a total of 4 weekly downloads. As such, b2f popularity was classified as not popular.
We found that b2f demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.