Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
environment
Advanced tools
Check which JavaScript environment your code is running in at runtime: browser, Node.js, Bun, etc
Check which JavaScript environment your code is running in at runtime
npm install environment
import {isBrowser, isNode} from 'environment';
if (isBrowser) {
console.log('Running in a browser!');
}
if (isNode) {
console.log('Running in Node.js!');
}
[!NOTE] Runtime checks should be used sparingly. Prefer conditional package exports and imports whenever possible.
isBrowser
Check if the code is running in a web browser environment.
isNode
Check if the code is running in a Node.js environment.
isBun
Check if the code is running in a Bun environment.
isDeno
Check if the code is running in a Deno environment.
isElectron
Check if the code is running in an Electron environment.
isJsDom
Check if the code is running in a jsdom environment.
isWebWorker
Check if the code is running in a Web Worker environment, which could be either a dedicated worker, shared worker, or service worker.
isDedicatedWorker
Check if the code is running in a Dedicated Worker environment.
isSharedWorker
Check if the code is running in a Shared Worker environment.
isServiceWorker
Check if the code is running in a Service Worker environment.
isMacOs
Check if the code is running on macOS.
isWindows
Check if the code is running on Windows.
isLinux
Check if the code is running on Linux.
isIos
Check if the code is running on iOS.
isAndroid
Check if the code is running on Android.
FAQs
Check which JavaScript environment your code is running in at runtime: browser, Node.js, Bun, etc
We found that environment demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.