
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
collections
Advanced tools
This package contains JavaScript implementations of common data structures with idiomatic iterfaces, including extensions for Array and Object.
You can use these Node Packaged Modules with Node.js, Browserify,
Mr, or any compatible CommonJS module loader. Using a module loader
or bundler when using Collections in web browsers has the advantage of
only incorporating the modules you need. However, you can just embed
<script src="collections/collections.min.js">
and all of the
collections will be introduced as globals. :warning:
require("collections")
is not supported.
npm install collections --save
Documentation can be found at http://collectionsjs.com which in turn can be updated at https://github.com/montagejs/collectionsjs.com.
Tests are in the test
directory. Use npm test
to run the tests in
NodeJS or open test/run.html
in a browser.
To run the tests in your browser, simply use npm run test:jasmine
.
To run the tests using Karma use npm run test:karma
and for continious tests run with file changes detection npm run test:karma-dev
. Finally to open a remote debug console on karma use npm run test:karma-debug
.
Array.prototype
with additional non-enumerable properties like .set
)FAQs
data structures with idiomatic JavaScript collection interfaces
The npm package collections receives a total of 52,631 weekly downloads. As such, collections popularity was classified as popular.
We found that collections demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.