
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
megadraft
Advanced tools
Rich Text editor built on top of Facebook's draft.js
Join the #megadraft channel on the DraftJS Slack team!
Checkout our website with a live demo!
To run the development server and see the examples:
git clone https://github.com/globocom/megadraft.git
cd megadraft/
make setup
make run
Note: make sure you're using node <14
Then visit http://localhost:8080/#/ on your browser.
To run local tests:
make unit
To lint local source files:
make lint
To run tests and lint:
make test
Megadraft depends on Sass to build style assets.
Megadraft ships with a default styling available at this location in the installed package: node_modules/megadraft/dist/css/megadraft.css.
Check out the docs for information about plugin structure. To help in this process there is a Yeoman Megadraft Plugin Generator.
Development of Megadraft happens in the open on GitHub, and we are grateful to the community for contributing bugfixes and improvements. Read below to learn how you can take part in improving Megadraft.
Read our contributing guide to learn about our development process, how to propose bugfixes and improvements, and how to build and test your changes to Megadraft.
Megadraft is licensed under the MIT license.
The Megadraft website uses a picture from Stocksnap.io by Tim Marshall licensed under CC0 license.
The Landing page uses a Megadeth picture by Ted Van Pelt licensed under CC-BY.
0.8.0 - 2023-01-04
media queries (#363)FAQs
Rich Text editor built on top of draft.js
The npm package megadraft receives a total of 1,491 weekly downloads. As such, megadraft popularity was classified as popular.
We found that megadraft demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 13 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.