
Research
/Security News
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two Joyfill npm beta releases contain an import-time implant that uses blockchain transactions to retrieve a remote-access trojan.
flex-decorators
Advanced tools
flexDecortors是使用TypeScript开发的用于简化装饰器开发的工具库。flexDecortors为开发装饰器提供了一套实践和规范,可以大大简化装饰器开发的开发,主要特性包括:
TypeScript开发装饰器管理器功能来处理公共的装饰器逻辑90%+测试覆盖VoerkaI18n: 基于Nodejs/React/Vue的一键国际化解决方案Logsets: 命令行应用增强输出库AutoPub: 基于pnpm/monorepo的自动发包工具FlexDecorators: JavaScript/TypeScript装饰器开发库FlexState: 有限状态机FlexTools: 实用工具函数库FAQs
[文档](https://zhangfisher.github.io/flex-decorators/)
The npm package flex-decorators receives a total of 48 weekly downloads. As such, flex-decorators popularity was classified as not popular.
We found that flex-decorators demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Two Joyfill npm beta releases contain an import-time implant that uses blockchain transactions to retrieve a remote-access trojan.

Security News
Socket releases free Certified Patches for high-severity Nuxt vulnerabilities, including server-side remote code execution through server island props.

Security News
An open letter signed by 50 companies, from NVIDIA and Microsoft to Mistral and Hugging Face, urges Washington not to restrict open weight AI.