Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Terminal client for cabal, the p2p chat platform.
See cabal-core for the underlying database & api.
chat with us:
npx cabal cabal://cabal-club.github.io
$ npm install --global cabal
$ cabal --key cabal://0201400f1aa2e3076a3f17f4521b2cc41e258c446cdaa44742afe6e1b9fd5f82
cabal --new
cabal --key <key>
e.g.
cabal --key cabal://0201400f1aa2e3076a3f17f4521b2cc41e258c446cdaa44742afe6e1b9fd5f82
This will run cabal without a UI. You can use this to seed a cabal (e.g. on a VPS) and make its data more available:
cabal --key <key> --seed
/channels
display channels you can join
/names
display a list of the people currently online
/join <channel>
join a channel
/j
alias for /join
/nick <new nick>
pick a new username
/n
alias for /nick
/emote <some text>
write an old-school text emote
/me
alias for /emote
/clear
clear the current backlog
/help
display a help message of the current commands
/quit
exit cabal
ctrl+u
clear input line
ctrl+w
delete last word in input
up-arrow
cycle through command history
down-arrow
cycle through command history
home
go to start of input line
end
go to end of input line
ctrl+n
go to next channel
ctrl+p
go to previous channel
pageup
scroll up through backlog
pagedown
scroll down through backlog
alt-[1,9]
select channels 1-9
alt-n
tab between the cabals & channels panes
FAQs
p2p chat
The npm package cabal-cli receives a total of 45 weekly downloads. As such, cabal-cli popularity was classified as not popular.
We found that cabal-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.