Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Plain JS tool for dragging bounding boxes on DOM elements. Handy to retrieve the relative position of the bounding box on the element.
npm install dragsnip
In your HTML code:
<div>
<img class="snippable" src="myImage.jpg" />
</div>
In your JS code:
let dragsnip = require("dragsnip");
// select the DOM element you want to dragsnip on (yep, that's a verb as of now)
let snip_area = document.getElementsByClassName("snippable");
// For now only relative coordinates are being delivered to the callback
let cb = (start, end) => {
console.log(`start: x: ${start.x} | y: ${start.y}`);
console.log(`end: x: ${end.x} | y: ${end.y}`);
};
// define options
const options = {
strokeColor: '#F0FFFF', // Defaults to '#000000'
}
// register your DOM element alongside with your callback
dragsnip.register(snip_area, cb, options);
// Profit. Try to click and drag on your image
FAQs
Dragging a selection on any enabled element
We found that dragsnip demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.