
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
cocoon-canvasplus
Advanced tools
Cocoon Canvas+ are multiplatform Javascript utilities that work in Canvas+. They are included in Canvas+ core, so it is not required to install anything else at the cloud. The required files, if so, will be injected automatically in your project. Only available in Cocoon.io projects.
The deviceready event fires when Cordova is fully loaded.
Unlike old CocoonJS plugins, Cocoon Canvas+ plugins need to wait for this event to start working.
document.addEventListener("deviceready", onDeviceReady, false);
function onDeviceReady() {
// Cocoon Canvas+ code here
}
You can learn more about Cordova events here
Canvas+ allows accessing a full DOM environment via Webview. Thus, there are two environments that live together: Canvas+ and WebView. Although both are two different JavaScript environments, Cocoon allows to render a transparent Webview on top of the Canvas+ OpenGL ES rendering context and it also provides a bidirectional communication channel between them. In this way, the final visual result seems to integrate both environments seamlessly.
However, as Cordova only injects automatically the required clobbers in the main webview engine, it is neccesary to add manually the following files to the content that will be sent and displayed in Canvas+ internal Webview:
Mozilla Public License, version 2.0
Copyright (c) 2015 Ludei
See MPL 2.0 License
FAQs
Cocoon Canvas+ =====================
The npm package cocoon-canvasplus receives a total of 0 weekly downloads. As such, cocoon-canvasplus popularity was classified as not popular.
We found that cocoon-canvasplus demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.