Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
$ yarn add cf-prefs
This native Node.js module allows you to read managed app preferences on macOS. It maps to the underlying CFPreferencesCopyAppValue
family of APIs. This module only truly works in apps with valid bundle IDs (i.e. Electron apps).
prefs.getPreferenceValue(key)
key
String - The preference key to fetch the value of, has to be a valid UTF-8 string.Returns String
| Integer
| Boolean
| Object
| Array
| undefined
Notes:
undefined
.Example:
console.log('My Preference Value:', prefs.getPreferenceValue('MyAppsCoolPreference'))
permissions.isPreferenceForced(key)
key
String - The preference key to determine if the value is forced, has to be a valid UTF-8 string.Returns Boolean
- Whether the preference key is "forced", if this method returns true you should not allow users to override this preference in your application as a system administrator has indicated this preference key is "forced". For more information check out the apple API docs.
FAQs
A native node module to access managed app preferences on macOS
The npm package cf-prefs receives a total of 481 weekly downloads. As such, cf-prefs popularity was classified as not popular.
We found that cf-prefs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.