
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
import-module-string
Advanced tools
import-module-stringUse import('data:') to execute arbitrary JavaScript strings. A simpler alternative to node-retrieve-globals that works in more runtimes.
export when used, otherwise implicitly export all globals (via var, let, const, function, Array or Object destructuring assignment, import specifiers, etc)import.meta.url when filePath option is suppliedaddRequire option adds support for require() (in Node)acorn for JS parsing only)512MB, Safari 2048MB, Firefox 512MB, Firefox prior to v137 32MBFAQs
Use import('data:') and import(Blob) to execute arbitrary JavaScript strings
The npm package import-module-string receives a total of 682 weekly downloads. As such, import-module-string popularity was classified as not popular.
We found that import-module-string demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.