
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
fire-starter
Advanced tools
A simple, lightweight, modern asset pipeline. Uses Pug (Jade) for markup, Sass for styles, Babel for Javascript (ES6+) and Grunt to compile, optimize, serve and watch. Support for S3 bucket uploading and Cloudfront invalidation is included.
Bundled with this project in a credentials.json.sample
file that should be renamed to credentials.json
and edited so it contains the correct credentials. An accessKeyId
and secretAccessKey
are required in order for deployment to work correctly. This file is gitignored by default.
Installation
# Install node modules - you only need to do this once :)
npm install
Development
# Starts a local server & watches for file changes
npm start
Deployment
# AWS
npm run deploy
Static Build
# Builds static, optimized assets to the dist directory
npm run build
jQuery is included by default, but you might not need it. To uninstall, just remove the dependency from bower.json
and the copy:jquery task (and references) in Gruntfile.js
. Also delete the jQuery scripts near the bottom of layout.pug
. If you don't need Bower either, you can delete that file all-together and remove the check bower dependencies section of Gruntfile.js
on lines 212-218, as well as the bower package from package.json
.
If you don't need AWS S3 and Cloudfront integration, just remove the aws and cloudfront tasks in Gruntfile.js
on lines 228-257 as well as the deploy task on line 263. There is a rename function on lines 156-158 that removes the .html extension from files to make the S3 urls look nice. You can remove that, as well as the grunt-aws package from package.json
and the credentials.json
file.
Built with ♥ at Mcleod Studio
FAQs
🔥 A simple, lightweight, modern asset pipeline.
The npm package fire-starter receives a total of 0 weekly downloads. As such, fire-starter popularity was classified as not popular.
We found that fire-starter demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.