
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
environment
Advanced tools
Check which JavaScript environment your code is running in at runtime: browser, Node.js, Bun, etc
Check which JavaScript environment your code is running in at runtime
npm install environment
import {isBrowser, isNode} from 'environment';
if (isBrowser) {
console.log('Running in a browser!');
}
if (isNode) {
console.log('Running in Node.js!');
}
[!NOTE] Runtime checks should be used sparingly. Prefer conditional package exports and imports whenever possible.
isBrowser
Check if the code is running in a web browser environment.
isNode
Check if the code is running in a Node.js environment.
isBun
Check if the code is running in a Bun environment.
isDeno
Check if the code is running in a Deno environment.
isElectron
Check if the code is running in an Electron environment.
isJsDom
Check if the code is running in a jsdom environment.
isWebWorker
Check if the code is running in a Web Worker environment, which could be either a dedicated worker, shared worker, or service worker.
isDedicatedWorker
Check if the code is running in a Dedicated Worker environment.
isSharedWorker
Check if the code is running in a Shared Worker environment.
isServiceWorker
Check if the code is running in a Service Worker environment.
isMacOs
Check if the code is running on macOS.
isWindows
Check if the code is running on Windows.
isLinux
Check if the code is running on Linux.
isIos
Check if the code is running on iOS.
isAndroid
Check if the code is running on Android.
FAQs
Check which JavaScript environment your code is running in at runtime: browser, Node.js, Bun, etc
The npm package environment receives a total of 4,732,841 weekly downloads. As such, environment popularity was classified as popular.
We found that environment demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.