
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
frontend-store
Advanced tools
封装 localStorage 和 sessionStorage,方法个数及方法调用方式与原对象一致,setItem 方法提供额外过期时间传参,且兼容原对象方法存储的数据。
封装 cookie,提供多个方法调用,简化操作。
npm i frontend-store
全局引入 <script src="https://unpkg.com/frontend-store/dist/index.js"></script> 暴露全局变量 frontendStore
import frontendStore from 'frontend-store'
// -- *storage* localStorage、sessionStorage用法一致 --
// key的类型都为string
frontendStore.localStorage.getItem(key)
// value: string | Record<string, any>
// expire?: number (过期时间戳:单位毫秒)
// frontendStore.localStorage.setItem('key', { name: '666' }, Date.now() + 1000 * 60 * 60 * 24)
frontendStore.localStorage.setItem(key, value, expire)
frontendStore.localStorage.removeItem(key)
frontendStore.localStorage.clear()
// -------------------------------------------
// *cookie*
// key的类型都为string
frontendStore.cookies.getItem(key)
// value: string
/*
* options:
* end?: number | string | Date
* domain?: string
* path?: string ()
* secure?: boolean (cookie 只会被 https 传输)
*/
/*
end
- 类型为number时,值为过期的秒数,永不过期为Infinity;
- 类型为string时,值为过期时间的 GMTString 格式;
- 类型为Date时,值为过期时间的 Date 对象;
- 如果没有定义则会在会话结束时过期。
path
- 例如 '/', '/mydir'。如果没有定义,默认为当前文档位置的路径。路径必须为绝对路径
domain
- 例如 'example.com','.example.com' (包括所有子域名), 'subdomain.example.com'。如果没有定义,默认为当前文档位置的路径的域名部分。
secure
- cookie 只会被 https 传输。
*/
frontendStore.cookies.setItem(key, value, options)
frontendStore.cookies.removeItem(key)
frontendStore.cookies.hasItem(key)
frontendStore.cookies.keys()
FAQs
frontend-store (前端存储工具封装) --- localStorage/sessionStorage/cookie
The npm package frontend-store receives a total of 4 weekly downloads. As such, frontend-store popularity was classified as not popular.
We found that frontend-store demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.