
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
cirru-parser
Advanced tools
Cirru is an indentation-based grammar. You may use it to create your own DSLs or scripting languages.
Find more at http://cirru.org/
npm install --save cirru-parser
{parse, pare} = require 'cirru-parser'
syntaxTree = parse code, filename
simplifiedTree = pare code, filename
info = caution char
parse(code, filename):Parse code in Cirru grammar, filename is optional:
A token in syntaxTree is like:
token =
text: 'get'
x: 0
y: 0
ex: 1
ey: 1
path: 'a.cirru'
And expressions here are just tokens in arrays, like:
expression = [
token
,
[
token
,
[
token
]
]
]
pare(code, filename):pare is short for parse, filename is optional.
simplifiedTree does not contain informations of files,
like line numbers, file content, which are needed in caution.
A token from pare is a string, i.e. the text field of parsing results.
Demo: http://repo.cirru.org/parser/ .
By typing on the left you should see the pare results on the right.
Detailed examples can be found in cirru/ and ast/ directories.
For short, there are then rules of Cirru:
"string"$ folds followed tokens in an expression, unfolds followed tokens in an expressionHere's a Gist showing how it's parsed(not including the steps solving $ and ,):
https://gist.github.com/jiyinyiyong/bdda3f616ff0f1bea917
This method was developed in [the Go version][go], you may check it out here.
Run tests:
gulp test
Also you may debug index.html in a browser after compiling the code:
npm i
gulp start
# view generated index.html in a web server
ex, ey from $x, $yMIT
FAQs
Cirru Parser in CoffeeScript
The npm package cirru-parser receives a total of 17 weekly downloads. As such, cirru-parser popularity was classified as not popular.
We found that cirru-parser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.