
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
bracket-split
Advanced tools
Bracket-aware split function, can be used to split a string containing JSON objects
This module can do bracket-aware splitting of strings!
const bracketSplit = require('bracket-split');
bracketSplit(
' ',
'{ "status": "ok" } [ "status" ] 2 3')
//-> [ '{ "status": "ok" }', '[ "status" ]', '2', '3' ]
bracketSplit(
delimiter,
str,
brackets = [ [ '{', '}' ], [ '[', ']' ] ],
quotes = [ '\'', '"' ],
escaper = '\\'
)
delimiter and str work as if you did str.split(delimiter)
brackets are pairs of brackets to treat specially, these will be checked for maching pairs in the str you are splitting, and errors may be thrown!
quotes are quote characters, brackets will be ignored if they are quoted (treated as plain strings)
escaper is a string to prefix another character in order to always treat it as a normal character (you can escape quotes and brackets to ignore them)
heredocs are pairs of brackets to treat as special overriding unnestable brackets, they support escaping and work a bit differently from normal brackets
Unexpected closing bracket: <closing bracket>
Unexpected end of input, expected: <quote or closing bracket>
FAQs
Bracket-aware split function, can be used to split a string containing JSON objects
We found that bracket-split demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.