Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
hs-poly-locator
Advanced tools
All of the client-side Locator and Directory code and markup.
cd
into the root directory of the theme where package.json
is located.npm install
gulp
app/
to build/
directory where the compiled version lives.gulp
and navigate to http://localhost:3000/ for testing (WIP)TODO: Handle this in the release process.
hs-poly-locator
npm package (Alex R. is a good resource for this)master
branchgit fetch && git rebase upstream/master
npm version 1.x.x
(1.x.x could be any new version tag you want to use)npm publish
FAQs
All of the client-side Locator and Directory code and markup.
We found that hs-poly-locator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.