
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
metro-file-map
Advanced tools
🚇 File system crawling, watching and mapping for Metro.
Originally a fork of jest-haste-map.
This entire package should be considered "experimental" for the time being - the API is considered internal and changes will not be semver-breaking.
If you need to rely on metro-file-map APIs directly please
raise an issue to discuss your
use case.
Chokidar is a highly efficient file watcher that can watch file system changes and trigger events. It is similar to metro-file-map's file watching feature but is more focused on watching and less on mapping and querying.
Glob is a package for matching files using patterns. It is similar to the file querying feature of metro-file-map but does not include file watching or mapping capabilities.
fs-extra extends the native Node.js file system module with additional methods. It provides some overlapping functionality with metro-file-map, such as file operations, but does not offer file watching or querying based on patterns.
FAQs
[Experimental] - 🚇 File crawling, watching and mapping for Metro
The npm package metro-file-map receives a total of 10,423,523 weekly downloads. As such, metro-file-map popularity was classified as popular.
We found that metro-file-map demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.