
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
complex-search
Advanced tools
npm install complex-search
Use this for complex, keyword-based search with the following operators:
|&()
("or", "and", and parens, "and" is the default)
Do not use it if you have high data volumes or so. Reason following below:
API:
var Search = require('complex-search')
var search = new Search("xml&(sax|parser)", function(results) {
console.log(results.join(", "))
})
search.keywords.forEach(function(keyword) {
callSomeAPIOrWhatever(keyword, function(keywordData) {
// keywordData is an array of strings, e.g. ["mycoolparser", "parser2", "parser3"]
search.provideKeywordData(keyword, keywordData)
})
})
As you can see, you need all results for each keyword. No problem if everything is on disk and you don't need this very often, but hell, don't think about it if you want to recreate Google or so.
FAQs
Search for stuff with &, | and parens
The npm package complex-search receives a total of 0 weekly downloads. As such, complex-search popularity was classified as not popular.
We found that complex-search demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.