
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
一个快速上手的百度车联网小程序脚手架, 轻松创建项目模板, 实现 0 配置, 快速开发。
Windows 系统安装
$ npm i iov-cli -g
Mac 下安装
$ sudo npm i iov-cli -g
$ iov
# 指定项目名字创建项目
$ iov create 模板名<template-name> 项目名字<project-name>
# 在当前目录创建项目
$ iov create 模板名<template-name> .
$ iov list
$ iov add 模板名<template-name> 模板github仓库地址,支持ssh/https格式<git-repo-address>
$ iov delete 模板名<template-name>
执行 pkg 下的脚本, 自动发版并且生成 changelog, travis 就会执行检测后续自动发到 npm.
npm run release
FAQs
a simple CLI for scaffolding of iov FE
We found that iov-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.