
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Web service worker to resolve es6 bare module specifiers.
allows the use of npm
installed package.json
dependencies in node_modules
as es6 module imports. eg.
index.html
<script type="module" src="index.mjs"></script>
index.mjs
import f, { n } from "some-lib";
f();
n();
Browsers that support es6 module loading only do so with relative or absolute paths. package.json dependencies referenced in import statements will not be resolved by browsers. baresm.js
will intercept bare module specifiers in javascript modules and rewrite them to absolute paths allowing you to use package.json dependencies in your module without any packaging / build stage of your code.
No. This is proof of concept and ultimately a stop-gap until browsers support bare module specifiers, if ever. The web specification for es6 module dependencies will likely look different to analyzing package.json files and resolving node_modules paths. Moreover, many typical/popular node_modules won't execute correctly without a packaging step directly in the browser and/or are very large and ultimatley unnecessary to deliver effectively your entire raw node_modules to browsers.
If you decide to use this:
npm install --save baresm
if you web server supports following symlinks, create a symlink as a sibling to your index.html, ie
ln -s node_modules/baresm/baresm.js .
otherwise, copy:
cp node_modules/baresm/baresm.js .
index.html
<script>
if ("serviceWorker" in navigator) {
window.addEventListener("load", () => navigator.serviceWorker.register("/baresm.js?your-version"));
}
</script>
replace your-version
with a version token that reflects your module and/or dependency changes.
have your index request serve Service-Worker-Allowed
header as /
so /node_modules/baresm/baresm.js
may use the root scope /
Service-Worker-Allowed: /
index.html
<script>
if ("serviceWorker" in navigator) {
window.addEventListener("load", () => navigator.serviceWorker.register("/node_modules/baresm/baresm.js?your-version", { scope: "/" }));
}
</script>
baresm.js
will create a node_modules
cache key and will effectively cache any fetch requests for your origin that are Content-Type application/javascript
. It is advised to version your service worker registration to ensure you reload this cache whenever you change your code and/or package dependencies.
FAQs
web service worker to resolve es6 bare module specifiers
The npm package baresm receives a total of 2 weekly downloads. As such, baresm popularity was classified as not popular.
We found that baresm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.