
Research
/Security News
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
load-script2
Advanced tools
Works in the browser with browserify!
npm install load-script2
This package works in the browser with browserify. If you do not use a bundler, you can use the standalone script directly in a <script>
tag.
const loadScript = require('load-script2')
const script = await loadScript('foo.js')
console.log(script.src);// Prints 'foo'.js'
load-script
load-script2
does not support legacy browsers like IE8 because these browsers
do not have standards-based DOM APIs. load-script2
also removes many esoteric
options, which aren't needed most of the time and adds promises support.
The size of load-script2
is 509 bytes, compared to 655 bytes for load-script
(minified
and gzipped).
promise = loadScript(src, [attrs], [parentNode])
Append a <script>
node with the given src
URL to the <head>
element in the DOM.
src
Any url that you would like to load. May be absolute or relative.
attrs
(optional)An object that contains HTML attributes to set on the <script>
tag. For
example, the value { id: 'hi' }
would set the attribute id="hi"
on the
<script>
tag before it is injected.
parentNode
(optional)The HTML node to which the <script>
tag will be appended. If not specified,
defaults to the <head>
tag.
promise
Returns a promise which resolves to the script
node that was appended to the
DOM, or rejects with err
if any occurred.
MIT. Copyright (c) Feross Aboukhadijeh.
FAQs
Dynamic script loading for modern browsers
The npm package load-script2 receives a total of 11,102 weekly downloads. As such, load-script2 popularity was classified as popular.
We found that load-script2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
Security News
Meet Socket at Black Hat & DEF CON 2025 for 1:1s, insider security talks at Allegiant Stadium, and a private dinner with top minds in software supply chain security.
Security News
CAI is a new open source AI framework that automates penetration testing tasks like scanning and exploitation up to 3,600× faster than humans.