
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
icomoon-generator
Advanced tools
icomoon-generator is a cross platform tool which create a new icomoon set.
Since icomoon do not provide any public API to use, you may found it's hard to integrate icomoon into your current workflow. icomoon-generator was made to solve this.
icomoon-generator will use your local Chrome to interact with icomoon in headless mode, so you need to make sure the latest version Chrome browser was installed.
Another dependency is the LTS version Node.js and all of those were isntalled as latest versions so we don't have any bulneralibity.
If you like to integrate icomoon-generator into your workflow, it's recommended to use in the programmatic way. You need a folder that you keep your svg files inside of it and you need to keep its name like me on svgDir. And you can choose the output folder of generated files.
// Install:
npm install --save-dev icomoon-generator
or
yarn add -D icomoon-generator
// Usage
const pipeline = require("icomoon-generator");
pipeline({
// If you add a selectionPath file you will add the svg icons over the existing one,
// But if you dont add a selectionPath icomoon-generator will use an empty selection.json file and will generate a new selection.json back to square one and will prepare just for the svg icons that are inside the svg folder
selectionPath: 'icons/selection.json',
outputDir: "icons",
svgDir: "svg",
forceOverride: true,
// visible: true,
whenFinished(result) {
// you can get the absolute path of output directory via result.outputDir
},
});
You can hack the downloaded icomoon files in a callback property whenFinished
, or just use Promise
to control your code since pipeline will return a promise.
FAQs
This is the best icomoon tool that you can ever seen
The npm package icomoon-generator receives a total of 1 weekly downloads. As such, icomoon-generator popularity was classified as not popular.
We found that icomoon-generator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.