
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
is-network-error
Advanced tools
Check if a value is a Fetch network error
This can be useful when you want to do something specific when a network error happens without catching other Fetch-related errors.
Unfortunately, Fetch network errors are not standardized and differ among implementations. This package handles the differences across Node.js, Bun, Deno, and browsers.
For instance, p-retry uses this package to retry on network errors.
npm install is-network-error
import isNetworkError from 'is-network-error';
async function getUnicorns() {
try {
const response = await fetch('unicorns.json');
return await response.json();
} catch (error) {
if (isNetworkError(error)) {
return localStorage.getItem('…');
}
throw error;
}
}
console.log(await getUnicorns());
isNetworkError(value: unknown): value is TypeErrorReturns true if the given value is a Fetch network error, otherwise false.
This function acts as a type guard, narrowing the type to TypeError when it returns true.
FAQs
Check if a value is a Fetch network error
The npm package is-network-error receives a total of 10,179,818 weekly downloads. As such, is-network-error popularity was classified as popular.
We found that is-network-error demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.