Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Boodle is an experimental ES6 ODM for parse.com backends. It lets you do delightful things like yield
for asynchronous tasks, directly get or set model values, and use the new ES6 class definitions.
co(function* () {
// shiny new es6 class syntax
class TestModel extends BaseModel {
// working on making this better, but...
get definition() {
return {
test: 'string'
};
}
}
// put a new model in the db
var createdModel = yield TestModel.generate();
var newToken = createdModel.token;
// re-fetch from the db
var loadedModel = yield TestModel.load(newToken);
// we can directly set model properties:
loadedModel.test = 'hello';
yield loadedModel.save();
// let's reload the model from the db for kicks
yield loadedModel.refresh();
// this will output 'hello'!
console.log(loadedModel.test);
// good bye model...
yield loadedModel.delete();
// this is null:
var deletedModel = yield TestModel.load(newToken);
});
FAQs
Boodle ======
We found that boodle demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.