
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
Gracefully cleanup when termination signals are sent to your process.
Because adding clean up callbacks for uncaughtException, SIGINT, and SIGTERM is annoying. Ideally, you can
use this package to put your cleanup code in one place and exit gracefully if you need to.
It's only been tested on POSIX compatible systems. Here's a nice discussion on Windows signals, apparently, this has been fixed/mapped.
npm install death
var ON_DEATH = require('death'); //this is intentionally ugly
ON_DEATH(function(signal, err) {
//clean up code here
})
By default, it sets the callback on SIGINT, SIGQUIT, and SIGTERM.
kill.More discussion and detail: http://www.gnu.org/software/libc/manual/html_node/Termination-Signals.html and http://pubs.opengroup.org/onlinepubs/009695399/basedefs/signal.h.html and http://pubs.opengroup.org/onlinepubs/009695399/basedefs/xbd_chap11.html.
AS they pertain to Node.js: http://dailyjs.com/2012/03/15/unix-node-signals/
No problem, do this:
var ON_DEATH = require('death')({uncaughtException: true})
Do this:
var ON_DEATH = require('death')({debug: true})
Your process will then log anytime it catches these signals.
Be careful with this one though. Typically this is fired if your SSH connection dies, but can also be fired if the program is made a daemon.
Do this:
var ON_DEATH = require('death')({SIGHUP: true})
Name it whatever you want. I like ON_DEATH because it stands out like a sore thumb in my code.
(MIT License)
Copyright 2012, JP Richardson jprichardson@gmail.com
FAQs
Gracefully cleanup when termination signals are sent to your process.
The npm package death receives a total of 280,424 weekly downloads. As such, death popularity was classified as popular.
We found that death demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.