
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
fxconsole
is a remote Javascript console for Firefox that runs in your terminal:
With node.js and the npm package manager:
npm install fxconsole -g
You can now use fxconsole
from the command line.
Enable remote debugging (You'll only have to do this once)
Open the DevTools. Web Developer > Toggle Tools
Visit the settings panel (gear icon)
Check "Enable remote debugging" under Advanced Settings
Listen for a connection
Open the Firefox command line with Tools > Web Developer > Developer Toolbar.
Start a server by entering this command: listen 6000
(where 6000
is the port number)
Follow the instructions in this short Hacks video
This one is a bit hacky right now, and object inspection doesn't work yet, but feel free to try. The .tabs
command lists the currently open apps in the simulator.
lsof -i -P | grep -i "b2g"
in Linux/Mac, or using fx-ports.fxconsole
and with the --port
argument.fxconsole --port 6000 --host 10.251.34.157
There are two extra REPL commands available beyond the standard node.js commands. .tabs
lists the open tabs in Firefox. .switch 2
switches to evaluating in a tab. The argument is the index of the tab to switch to.
FAQs
This package is no longer supported and has been deprecated. To avoid malicious use, npm is hanging on to the package name.
The npm package fxconsole receives a total of 3 weekly downloads. As such, fxconsole popularity was classified as not popular.
We found that fxconsole demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.