
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Browserify transform to ensure all dependencies exist in a case-sensitive environment
Browserify transform to ensure all dependencies exist in a case-sensitive environment. Checks that all require
expressions with relative paths point to a file that can be found using a case preserving string match.
Useful for detecting issues in case sensitive module naming on case-insensitive dev machines (such as OS X and WinX) that end up causing issues on Linux based Continuous Integration machines.
npm install --save-dev caseify
install as dev dependency'caseify'
as a browserify transform via {
"browserify": {
"transform": [ "caseify" ]
}
}
or if using Gulp or Grunt, simply add 'casefiy'
to your list of transforms.
To configure how caseify works, add setting in your project's package.json
file under caseify
.
relativePaths
: Default false
- show file paths as relative to the current working directory
throwOnError
: Default fasle
- throw a fatal error if an invalid module is found. This is instead of the default behaviour which emits an error on the browserify stream. Note: this will occur before browserify has processed the file and interrupt it immediately.
eg. package.json
...
"devDependencies": {
"caseify": "~0.1"
},
"caseify": {
"relativePaths": true,
"throwOnError": true
},
...
Within this directory structure:
moduleA.js
|-- deps/moduleB.js
|-- deps/moduleC.js
if moduleA.js contains:
var moduleB = require('./deps/moduleb');
running: browserify -t caseify module*.js > module.bundle.js
causes this output:
Caseify: /Users/jmoses/example/moduleA.js module ./deps/moduleb not found in case-sensitive environment
FAQs
Browserify transform to ensure all dependencies exist in a case-sensitive environment
The npm package caseify receives a total of 2 weekly downloads. As such, caseify popularity was classified as not popular.
We found that caseify demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.