
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
自动完成每日任务领取积分
首先拉取用户已下发的任务, 下面的任务没有的会跳过执行
日常登录 1 积分
阅读 3 篇题解 1 积分(暂时取消)
每日登录领取 1 积分
保存一则学习笔记 3 积分
阅读 3 章 LeetBook 领取 2 积分
获取 2 本免费的 LeetBook 领取 3 积分
点赞一则 LeetBook 讨论 领取 1 积分
# clone project
git clone https://github.com/xjq7/lc-helper
# cd folder
cd lc-helper
# 安装 pnpm, 已安装的话就跳过
npm install pnpm -g
# 依赖安装
pnpm install
pnpm dev <account> <password>
# 编译
pnpm tsc
# link 到全局
npm link --force
# 运行
lchl start <account> <password>
目前只支持账号密码登录
# 全局安装
npm install -g lchl
# or
yarn global add lchl
# 运行
lchl start <account> <password>
# example
lchl start 16618922034 123456
通过 Github Action 每天凌晨 00:50 分自动执行, 需要提前配置账号密码在 Action Secret 中
fork 本项目
配置账号密码用于工具登录
创建 Github action Secret
进入你 fork 的项目, 找到 Settings - Security - Secrets - Actions
然后 点击新建 New repository secret
填写一个 Name 为 ACCOUNT 的 key, Secret 为你的账号
填写一个 Name 为 PASSWORD 的 key, Secret 为你的密码
点击 Actions, 找到定时任务 auto action runner
第一次接入手动触发任务测试是否有问题
点击 Run workflow 手动触发任务
点击进入 当前执行的 Action 中查看日志
run 环节会打印执行结果
后续每天 00:50 自动执行, 时间可能有误差, 00:50 ~ 01:00 之间
FAQs
力扣限制又严格了一些, 需要抓包 App 获取两个认证 token
The npm package lchl receives a total of 3 weekly downloads. As such, lchl popularity was classified as not popular.
We found that lchl demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.