Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Sorry, this was thrown together as fast as possible. I'll update it to use browserify object and not command line, and better exclusion of other libraries.
An automation tool for building modules with browserify
This plugin requires Grunt ~0.4.1
If you haven't used Grunt before, be sure to check out the Getting Started guide, as it explains how to create a Gruntfile as well as install and use Grunt plugins. Once you're familiar with that process, you may install this plugin with this command:
npm install manifest.json --save-dev
Once the plugin has been installed, it may be enabled inside your Gruntfile with this line of JavaScript:
grunt.loadNpmTasks('manifest.json');
Mission Statement: To create a reliable, fast build process with low overhead and maintenance.
Note, please use relative pathing within the Manifest.JSON file and within grunt.
grunt.initConfig({
manifest_json: {
build1: {
options: {
dist: './dist',
files: './package/manifest.json'
}
}
},
})
{
"requires": [
"core.js:core",
"../components/jquery/jquery.min.js:jquery",
"lodash",
"q"
],
"ignores": [],
"excludes": [],
"entry": "core.js",
"bundle": "js-core.js"
}
dist
The none-required distribution folder to put the bundle. Will work in conjuction with cwd
cwd
The current working directory all of these files should be considered relative from. This does not apply to the Manifest.JSON filesall
Will compile every manifestFile
from the Gruntfile
root.manifestFile
The name of the manifest file. Default: manifest.json
requires
An array of files to be exposed for other bundles (aka externalize). A :
can be used to give the require an easier name. ./lib/awesome_lib/awesome.js:awesome
externals
Will be treated as externals and not included within the source bundle.externalFolders
Will find every js
file and external
it.bundle
The name of the bundle to compile toentry
The file(s) (String or Array) of entry points.FAQs
An automation tool for building modules with browserify
The npm package build.json receives a total of 2 weekly downloads. As such, build.json popularity was classified as not popular.
We found that build.json demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.