
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
element-notifier
Advanced tools
A MutationObserver dis/connected helper.
import {notify} from 'element-notifier';
const observer = notify(
// callback that receives any connected/disconnected element
(element, connected) => {
if (connected)
console.log(element, 'has been connected');
else
console.log(element, 'has been disconnected');
},
// optional arguments
document, // the root element to observe
MutationObserver // a MutationObserver (non DOM envs)
);
The observer
is a regular MutationObserver instance with a self bound, and instrumented, .observe(node)
method to observe mutations within fragments too (example: shadowRoot nodes).
The MutationObserver dance with records is easily error prone:
This helper does just this: it passes to the callback every element that has been added, or removed, from the document.
While the observer could crawl nodes within a shadowRoot
, in case it's opened, if nodes are removed from it nothing is notified due MutationObserver limitations.
If observing nodes appended or removed from any shadowRoot
is desired, or at least any open one, it is necessary to somehow pollute the Element.prototype
in a similar way:
import {notify} from 'element-notifier';
// augmented method with right options included
const {observe} = notify(/* ... */);
const {attachShadow} = Element.prototype;
Element.prototype.attachShadow = function (init) {
const shadowRoot = attachShadow.call(this, init);
if (init.mode === 'open')
observe(shadowRoot);
return shadowRoot;
};
It is not responsibility of this module to augment the environment so it's up to this module consumers decide if doing so is needed or desired.
Please note that connected
might mislead in case the shadowRoot is not live yet, as the MutationObserver in fragments doesn't care about their owner state.
FAQs
A MutationObserver dis/connected helper
We found that element-notifier demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.