
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Monitor your asset size over time, in your browser, or using the provided HTTP API.
Monitor your asset size over time, in your browser, or using the provided HTTP API.
Demo: collecting data every 12 hours.
This is my first Node app, I know it is messy and it still lacks tests.
More features to come: see roadmap.
npm install -g moniteur
Usage: moniteur [options] [command]
Commands:
record grab a snapshot of all asset metrics
serve see assets sensor graphs in the browser
Options:
-h, --help output usage information
-V, --version output the version number
-c, --config [path] specify a configuration file
Create a moniteur.json
file in the directory where asset sizes
should be stored (typically: the root directory of your project):
{
"assets": {
"My main CSS": "public/stylesheets/main.css",
"My bundle of CSS files": [
"core.css",
"head.css",
"index.css",
"global.css"
],
"Remote stylesheet": "http://path/to/styles.css",
"Remote JavaScript": "http://path/to/styles.js",
"Single JavaScript file": "public/javascripts/app.js",
"Bundle of JavaScript files": [
"module-a.js",
"module-b.js",
"module-c.js",
"dependency.js"
]
}
}
Note: moniteur
will load moniteur.json
file in your home directory
or the current directory.
Moniteur relies on the NODE_ENV
environment variable to select a database:
{
"assets": {
// Stylesheets, scripts…
},
"db": {
"development": {
"engine": "filesystem",
"directory": ".moniteur"
},
"production": {
"engine": "redis",
"url": "redis://localhost:6379"
}
}
}
For now, two types of storage are supported: Redis and local filesystem.
A confidential Redis URL can be passed through an environment variable, instead of having it stored in the configuration file:
DB_URL=redis://rediscloud:XXXX@pub-redis-XXXX.us-east-X-X.X.ec2.garantiadata.com:13714
Run your application like this:
DB_URL=redis://url moniteur [options]
Clone the repository and run:
npm run dev
Takes a snapshot of asset metrics and stores them in the .moniteur/
directory.
moniteur record --config ../test/fixtures/test-config.json
/config
Since forever:
/metrics/stylesheets/adf6e9c154cb57a818f7fb407085bff6
Between two dates:
/metrics/stylesheets/adf6e9c154cb57a818f7fb407085bff6/1015711104475..1415711104475
MIT
Acknowledgments: "merci" to https://github.com/t32k/stylestats, which has been a great source of inspiration.
moniteur init
, a moniteur.json configuration file generator, with
interactive menusFAQs
Monitor your asset size over time, in your browser, or using the provided HTTP API.
The npm package moniteur receives a total of 0 weekly downloads. As such, moniteur popularity was classified as not popular.
We found that moniteur demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.