Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Example repo: https://github.com/ykan/ykan.github.com
Result: http://ykan.github.io/blog/
~ npm install cldoc -g
仓库必须包含以下两个目录:
- documents //存放文档
- common // 类目目录,可以自己新建文件夹
- README.md //目录的根页面,会被渲染为index.html,比如common/README.md,会生成common/index.html
- example.md // -> common/example.md.html
- example.ignore.md //注意:如果字符中包含了ignore,那么这个文件将会再导航中被忽略
- README.md // -> index.html 生成最外层的根页面
- models // 存放数据模型
- example.json
~ cldoc <outputDir> #输出文件夹
FAQs
Example
The npm package cldoc receives a total of 4 weekly downloads. As such, cldoc popularity was classified as not popular.
We found that cldoc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.