
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
homebridge-controllerlink
Advanced tools
Provides a link for the HomeBridge Controller app to HomeBridge
This repository contains the HomeBridge Controller Link plugin for homebridge, which allows the HomeBridge Controller app a way to interact with your homebridge, no matter where on the local network it is installed. For more information, please see the main GitHub repo.
Configuration sample:
"platforms": [
{
"platform": "HomeBridgeControllerLink",
"restartStyle": "respawn",
"disableAutoRestart": false,
"disableLogger": false
}
],
"restartStyle" - Optional config to specify how the restart should be handled: - "respawn" (default) : Spawns a new instance of homebridge when restarted - "stopOnly" : Only shutsdown and then exits with exitCode 1 "disableAutoRestart" - Optional config that can disable auto restarting homebridge when an unhandled error occurs (which will cause homebridge to crash) "disableLogger" - Optional config that can disable the automatic file logging as well as the streaming of the logs
FAQs
NodeJS connection to HomeBridgeController
We found that homebridge-controllerlink demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.