
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
browser-signature
Advanced tools
Browser unique signature (Fingerprint) generator
This is a simple and tiny (<1kb) package for generating unique user browser signature or fingerprint.
The package allow you to identify user online using their browser unique signature
The package have two implementations:
Browser unique fingerprint or signature generation using the hash of browser mimeTypes count + userAgent string length + global properties count + screen property values.
Available in four formats:
dist/browser-signature.m.js
dist/browser-signature.js
dist/browser-signature.modern.js
dist/browser-signature.umd.js
Radom String generation and persisting in the browser local storage. The same string is return every time by the package from the local storage.
Available in four formats:
dist/storage.m.js
dist/storage.js
dist/storage.modern.js
dist/storage.umd.js
$ npm install --save browser-signature
import browserSignature from 'browser-signature';
const signature = browserSignature();
console.log("Current Browser Unique Signature: ", signature);
// Result will look like => 'Current Browser Unique Signature: MjY2NjE4Z3AwMThnbXpvbw=='
<script src="https://cdn.jsdelivr.net/npm/browser-signature@1.0.5/dist/browser-signature.umd.js" ></script>
or
<script src="https://unpkg.com/browser-signature@1.0.5/dist/browser-signature.umd.js"></script>
const signature = browserSignature();
console.log("Current Browser Unique Signature: ", signature);
// Result will look like => 'Current Browser Unique Signature: MuY1NjE9b3swpTknbXpvbw=='
import browserSignature from 'browser-signature/dist/storage';
const signature = browserSignature();
console.log("Current Browser Unique Signature: ", signature);
// Result will look like => 'Current Browser Unique Signature: po3wmbl6ukeky165ydtaqjqgfn7865gertuxqeydlfn1jixt4idjzd'
<script src="https://cdn.jsdelivr.net/npm/browser-signature@1.0.5/dist/storage.umd.js" ></script>
or
<script src="https://unpkg.com/browser-signature@1.0.5/dist/storage.umd.js"></script>
const signature = browserSignature();
console.log("Current Browser Unique Signature: ", signature);
// Result will look like => 'Current Browser Unique Signature: po3wmbl6ukeky165ydtaqjqgfn7865gertuxqeydlfn1jixt4idjzd'
Returns: String
FAQs
Browser unique signature (Fingerprint) generator
The npm package browser-signature receives a total of 2,251 weekly downloads. As such, browser-signature popularity was classified as popular.
We found that browser-signature demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.