
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
homebridge-z2m
Advanced tools
Expose your Zigbee devices to HomeKit with ease, by integrating Zigbee2MQTT with Homebridge.
Expose your Zigbee devices to HomeKit with ease, by integrating 🐝 Zigbee2MQTT with 🏠 Homebridge (via an MQTT message broker).
This Homebridge plugin can be installed using npm install homebridge-z2m or via the Homebridge Config UI X plugin.
The bare minimum configuration for this plugin only has to contain the MQTT server information:
{
"platform": "zigbee2mqtt",
"mqtt": {
"base_topic": "zigbee2mqtt",
"server": "mqtt://localhost:1883"
}
}
After adding this to your configuration and restarting Homebridge, it should automatically retrieve all the required information about the devices from Zigbee2MQTT (via the configured MQTT server).
For more information on installing, configuring and using the plugin, please check the documentation on the plugin website.
If you have a question or run into a problem, please ask a question in the #z2m channel on the Homebridge Discord. I also try to check the homebridge subreddit for Zigbee and Zigbee2MQTT every now and then (but you'll probably get a faster answer on Discord).
This project is open to contributions. Please read the CONTRIBUTING.md file for more information.
[1.9.3] - 2024-01-03
v1.9.3-rc.0)FAQs
Expose your Zigbee devices to HomeKit with ease, by integrating Zigbee2MQTT with Homebridge.
The npm package homebridge-z2m receives a total of 193 weekly downloads. As such, homebridge-z2m popularity was classified as not popular.
We found that homebridge-z2m demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.