
Research
npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
gulp-inject-string
Advanced tools
Inject snippets in build
append(str) // Appends the string
prepend(str) // Prepends the string
wrap(start, end) // Wraps file contents in between *start* and *end*
before(search, str) // Inserts the string before the first occurence of *search*
after(search, str) // Inserts the string after the first occurence of *search*
beforeEach(search, str) // Inserts the string before each occurence of *search*
afterEach(search, str) // Inserts the string after each occurence of *search*
replace(search, str) // Replaces each occurence of *search* with *str*
See examples/build for output.
var gulp = require('gulp'),
rename = require('gulp-rename'),
inject = require('gulp-inject-string');
gulp.task('inject:append', function(){
gulp.src('src/example.html')
.pipe(inject.append('\n<!-- Created: ' + Date() + ' -->'))
.pipe(rename('append.html'))
.pipe(gulp.dest('build'));
});
gulp.task('inject:prepend', function(){
gulp.src('src/example.html')
.pipe(inject.prepend('<!-- Created: ' + Date() + ' -->\n'))
.pipe(rename('prepend.html'))
.pipe(gulp.dest('build'));
});
gulp.task('inject:wrap', function(){
gulp.src('src/example.html')
.pipe(inject.wrap('<!-- Created: ' + Date() + ' -->\n', '<!-- Author: Mike Hazell -->'))
.pipe(rename('wrap.html'))
.pipe(gulp.dest('build'));
});
gulp.task('inject:before', function(){
gulp.src('src/example.html')
.pipe(inject.before('<script', '<script src="http://code.jquery.com/jquery-2.1.1.min.js"></script>\n'))
.pipe(rename('before.html'))
.pipe(gulp.dest('build'));
});
gulp.task('inject:after', function(){
gulp.src('src/example.html')
.pipe(inject.after('</title>', '\n<link rel="stylesheet" href="test.css">\n'))
.pipe(rename('after.html'))
.pipe(gulp.dest('build'));
});
gulp.task('inject:beforeEach', function(){
gulp.src('src/example.html')
.pipe(inject.beforeEach('</p', ' Finis.'))
.pipe(rename('beforeEach.html'))
.pipe(gulp.dest('build'));
});
gulp.task('inject:afterEach', function(){
gulp.src('src/example.html')
.pipe(inject.afterEach('<p', ' class="bold"'))
.pipe(rename('afterEach.html'))
.pipe(gulp.dest('build'));
});
gulp.task('inject:replace', function(){
gulp.src('src/example.html')
.pipe(inject.replace('test.js', 'test.min.js'))
.pipe(rename('replace.html'))
.pipe(gulp.dest('build'));
});
gulp.task('default', [
'inject:append',
'inject:prepend',
'inject:wrap',
'inject:before',
'inject:after',
'inject:beforeEach',
'inject:afterEach',
'inject:replace'
]);
replace
. Thanks alexweber.After a year with no changes or issues, this might as well be a 1.0. It will probably never change again.
FAQs
Inject snippets in build
The npm package gulp-inject-string receives a total of 11,713 weekly downloads. As such, gulp-inject-string popularity was classified as popular.
We found that gulp-inject-string demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
Security News
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
Product
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.