
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
check-anything
Advanced tools
npm i check-anything
Check anything from URLs to Email addresses.
import { isUrl, isHttpsUrl, isEmail } from 'check-anything'
isHttpsUrl('https://github.com') // true
isUrl('ftp://foo.bar/baz') // true
isEmail('me@github.com') // true
You usually want to use isHttpsUrl
instead of isUrl
. It will limit the URLs to just regular https://
urls and also has the smallest footprint.
isHttpsUrl
is opiniated, it will return false
for the following list to keep the source code small and simple.
import { isHttpsUrl } from 'check-anything'
// returns true:
isHttpsUrl('https://github.com')
isHttpsUrl('https://ギットハブ.com') // special characters in domain
isHttpsUrl('https://github.com/ギットハブ') // special characters in URI
// returns false:
isHttpsUrl('http://github.com') // http
isHttpsUrl('ftp://foo.bar/baz') // ftp
isHttpsUrl('https://142.42.1.1/') // ip
isHttpsUrl('https://userid:password@example.com') // password
isHttpsUrl('mailto:me@github.com') // mailto URLs
isUrl
on the other hand will return true
for all of these, except for the mailto:
URL.
import { isUrl } from 'check-anything'
// returns true:
isUrl('https://github.com')
isUrl('https://ギットハブ.com') // special characters in domain
isUrl('https://github.com/ギットハブ') // special characters in URI
isUrl('http://github.com') // http
isUrl('ftp://foo.bar/baz') // ftp
isUrl('https://142.42.1.1/') // ip
isUrl('https://userid:password@example.com') // password
// returns false:
isUrl('mailto:me@github.com') // mailto URLs
Let me know if you are interested in any of these functions, I will consider adding them:
isProbableUrl
— to allow URLs like 'github.com'
without protocol (has chance of failure though)isFtpUrl
isPasswordUrl
isIpUrl
isMailtoUrl
FAQs
Check anything from URLs to Email addresses
We found that check-anything demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.