
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
bobbi-lisp-audio
Advanced tools
Audio engine for bobbi-lisp based on the Web Audio API
playSong -> (notes, tempo)
notesnotes is a vector of maps which must have the following keys:
instrument: The audio sample file to be played.
pitch: A midi number, an integer representing the frequency. Middle C is 60.
time: The beat number at which the note is to occur.
tempoTempo is an integer representing the number of beats per minute.
This would play a major scale:
[{:instrument "1.mp3" :pitch 60 :time 0}
{:instrument "1.mp3" :pitch 62 :time 1}
{:instrument "1.mp3" :pitch 64 :time 2}
{:instrument "1.mp3" :pitch 65 :time 3}
{:instrument "1.mp3" :pitch 67 :time 4}
{:instrument "1.mp3" :pitch 69 :time 5}
{:instrument "1.mp3" :pitch 71 :time 6}
{:instrument "1.mp3" :pitch 72 :time 7}]
Of course it would be very tedious to write music that way. Fortunately we have all the power of function composition to generate them. See demo.clj for a complete arrangement, and SimLispy for an example of how to use it in your project. Visit https://www.youtube.com/watch?v=giPlacLrC5g to see and hear it if you are so able.
FAQs
Audio engine for bobbi-lisp based on the Web Audio API
We found that bobbi-lisp-audio demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A malicious package uses a QR code as steganography in an innovative technique.

Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.

Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.