
Research
NPM targeted by malware campaign mimicking familiar library names
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
convert-vapid-public-key
Advanced tools
[](https://github.com/screendriver/convert-vapid-public-key/actions) [ {
const registration = await navigator.serviceWorker.register("service-worker.js");
const subscribeOptions = {
userVisibleOnly: true,
applicationServerKey: convertVapidKey("<your-base64-vapid-public-key>"),
};
const pushSubscription = await registration.pushManager.subscribe(subscribeOptions);
// ...
}
FAQs
[](https://github.com/screendriver/convert-vapid-public-key/actions) [ to exfiltrate data and execute commands.