
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
nativescript-opentok
Advanced tools
A Nativescript plugin for the OpenTok iOS and (coming soon Android) SDK.
OpenTok: https://tokbox.com/developer/
Node Package Manager (NPM)
npm install nativescript-opentok --save
You will first need to import the custom element into the {N} xml view. This can be accomplished by adding this snippet: xmlns:OT="nativescript-opentok"
to your existing Page
element tag.
The basic integration example would include the following declarations for publisher and subscriber. Notice subscriber is any element with id="subscriber"
.
<StackLayout id="subscriber" width="100%" height="100%"></StackLayout>
<OT:TNSOTPublisher id="publisher" verticalAlignment="top" horizontalAlignment="right" margin="10" width="100" height="100"></OT:TNSOTPublisher>
Next in your page's binding context (a controller, view model, etc.), you will need to import and hook to the OpenTok implementation.
import {TNSOTPublisher, TNSOTSession} from 'nativescript-opentok';
public _apiKey:string = 'API_KEY';
public sessionId: string = 'SESSION_ID';
public publisherToken: string = 'TOKEN';
private publisher: TNSOTPublisher;
private session:TNSOTSession;
constructor(private page: Page) {
super();
this.session = TNSOTSession.initWithApiKeySessionId(this._apiKey, this.sessionId);
this.publisher = <TNSOTPublisher> this.page.getViewById('publisher');
this.initPublisher();
}
initPublisher() {
this.session.connect(this.publisherToken);
this.publisher.publish(this.session);
}
iPhone | iPad |
---|---|
![]() | ![]() |
TNS
stands for Telerik NativeScriptFAQs
Integrates OpenTok for NativeScript.
The npm package nativescript-opentok receives a total of 16 weekly downloads. As such, nativescript-opentok popularity was classified as not popular.
We found that nativescript-opentok demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.