
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
SDK for IBM DX.
npm install gulp -g
(you may need to run it as root)npm install jspm@beta -g
(you may need to run it as root)npm install typings -g
(you may need to run it as root)npm install && jspm install && typings install
npm start
In order for users to use paths like @mabel/core/some-module
all the compiled files need to live in the root of the published package. To accomplish this, only the dist
folder is published.
To publish a new version run:
gulp build
dist
npm publish --access=public
You may need to login first https://docs.npmjs.com/cli/adduserbuild
: Same as npm start
. Builds the source code and prepares it for production (inside the dist/ folder)build:prepare-npm-package
: Prepares the dist
folder to be ready for publishing it to npmbuild:prepare-npm-package:copy-docs
: Copies common doc files to the dist
folder so they can be published in the npm packagebuild:prepare-npm-package:copy:package-json
: Copies a modified version of this project's package.json. This modified version is the one that will be published to npmbuild:sfx
: Bundles the source code into a single sfx executable dist/bundles/core.sfx.js
compile:typescript
: Compiles all the typescript source code and makes it accessible in the dist
folderclean:dist
: Cleans the dist
folderdefault
: Same as build
lint
: Lints the whole project to check that the code style is being followedlint:typescript
: Lints typescript files@mabel/core
and exposes it in the global environment.Copyright (c) 2015-present, Base22 Technology Group, LLC.
All rights reserved.
This source code is licensed under the BSD-style license found in the
LICENSE file in the root directory of this source tree.
FAQs
SDK for IBM DX
The npm package mabel receives a total of 1 weekly downloads. As such, mabel popularity was classified as not popular.
We found that mabel demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.